IPsec Helper
MITRE ATT&CK: S1132 View on attack.mitre.org
Aliases: IPsec Helper
- First seen
- 2021-11-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:21:14
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:il
Context
IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.
Detection coverage
- 434 Sigma rules
Malware & tools used
- Indicator Removal (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Process Discovery (attack-pattern)
- Clear Persistence (attack-pattern)
- Modify Registry (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- PowerShell (attack-pattern)
- Visual Basic (attack-pattern)
- Data from Local System (attack-pattern)
- Windows Command Shell (attack-pattern)
- Time Based Checks (attack-pattern)
- Web Protocols (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Service Execution (attack-pattern)
- File Deletion (attack-pattern)
Used by threat actors
- Agrius (threat-actor)
Reports & references
- assets.sentinelone.com — Evol Agrius (report)
- MITRE ATT&CK — S1132 (report)