https://www.proofpoint.com/us/threat-insight/post/servhelper-and-flawedgrace-new-malware-introduced-ta505
FlawedGrace
FlawedGrace, also known as GraceWire, is a Windows remote access trojan and backdoor written in C++ that has been active since at least 2017.
Profile source: Mallory opens in a new tabFlawedGrace
Family profile
FlawedGrace, also known as GraceWire, is a Windows remote access trojan and backdoor written in C++ that has been active since at least 2017. It is a full-featured post-compromise implant associated most closely with the financially motivated TA505 cluster and has also appeared in operations linked to Evil Corp and in intrusion chains involving TrueBot. FlawedGrace has been used as a second-stage payload following loaders and downloaders such as ServHelper, Get2, MirrorBlast, KiXtart- and REBOL-based intermediaries, and TrueBot, and it has also been observed in intrusions that later culminated in enterprise ransomware deployment, including Clop-related activity.
The malware provides hands-on remote control of infected systems and supports standard RAT functionality including command execution, file transfer, script execution, and remote desktop-related capabilities. Public reporting also describes password-stealing functionality, process injection into legitimate Windows processes, encrypted payload storage, and persistence mechanisms including scheduled-task abuse and registry-based storage. In some observed activity, operators abused a legitimate backup-related scheduled task and its COM handler to load FlawedGrace for persistence. Government reporting has additionally described registry modification, use of print-spooler-related components for persistence or privilege escalation, and injection into system processes to establish command-and-control connectivity.
FlawedGrace uses an encrypted custom binary command-and-control protocol, commonly over TCP port 443, and stores configuration data in encrypted form. Reverse-engineering reporting has characterized its networking stack as sophisticated and noted use of a custom virtual filesystem for configuration management and command-and-control operations. Later variants introduced stronger obfuscation, including encrypted strings, obfuscated API resolution, and encrypted configuration storage in resources, memory, and the registry.
Distribution has most often been tied to phishing-driven intrusion chains. TA505 campaigns delivered precursor malware through malicious Office documents, macro-enabled Excel attachments, HTML redirectors, landing pages impersonating file-sharing services, and related social-engineering lures. Those initial stages then retrieved intermediate loaders or downloaders that ultimately deployed FlawedGrace. It has also been observed after exploitation-based access, including activity involving Netwrix Auditor and SolarWinds Serv-U compromises, as well as in campaigns where Raspberry Robin or TrueBot served as upstream delivery mechanisms.
FlawedGrace has been used against a broad range of sectors rather than a single niche. Reported targeting associated with its operators includes financial institutions, retail, restaurants, healthcare, education, government, and other enterprise environments across multiple regions. Its role in these operations is typically as a durable foothold and operator-controlled backdoor that enables deeper compromise, follow-on tooling, credential theft, lateral movement, and preparation for monetization through ransomware or other financially motivated objectives.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Privilege Escalation
- Process Injection
Reported operators
Threat actors
2 named in public reportingResearchers thought EvilCorp to be linked to TrueBot due to TrueBot dropping FlawedGrace. FlawedGrace is malware that is attributed to EvilCorp.
Exploited software
Vulnerabilities linked to FlawedGrace
1 CVEsMITRE ATT&CK