IPsec Helper — Malware Profile
IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.
MITRE ATT&CK techniques (15)
- T1005 Data from Local System
- T1027.013 Encrypted/Encoded File
- T1041 Exfiltration Over C2 Channel
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1070 Indicator Removal
- T1070.004 File Deletion
- T1070.009 Clear Persistence
- T1071.001 Web Protocols
- T1112 Modify Registry
- T1497.003 Time Based Checks
- T1569.002 Service Execution
- T1570 Lateral Tool Transfer