IPsec Helper

MITRE ATT&CK: S1132 View on attack.mitre.org

Aliases: IPsec Helper

First seen
2021-11-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:21:14

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:il

Context

IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.

Detection coverage

  • 434 Sigma rules

Malware & tools used

  • Indicator Removal (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Process Discovery (attack-pattern)
  • Clear Persistence (attack-pattern)
  • Modify Registry (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • PowerShell (attack-pattern)
  • Visual Basic (attack-pattern)
  • Data from Local System (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Web Protocols (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Service Execution (attack-pattern)
  • File Deletion (attack-pattern)

Used by threat actors

Reports & references

  • assets.sentinelone.com — Evol Agrius (report)
  • MITRE ATT&CK — S1132 (report)

External references