IPsec Helper is a custom .NET backdoor associated with the Iran-linked threat actor Agrius and appears to be exclusive to that group. It has been deployed post-exploitation on selected hosts, including in campaigns targeting organizations in Israel and elsewhere in the Middle East beginning in 2020. Agrius registered IPsec Helper as a Windows service for persistence, and the malware is run as a Windows service in victim environments. SentinelLabs assessed with medium confidence that Agrius is affiliated with Iran.
Based on the provided content, IPsec Helper supports multiple post-compromise functions. It can receive commands from an attacker-controlled server, exfiltrate specific files over its command-and-control channel, and be used to deploy additional malware; reporting also notes it can download and execute an executable file. It can run arbitrary PowerShell commands and arbitrary Visual Basic scripts/commands passed to it, and it can make arbitrary changes to registry keys based on provided input. For defense evasion and cleanup, it can delete various registry keys related to its execution and use. It also includes time-based evasion behavior, sleeping for a random number of seconds across 200 iterations of one- to three-second delays before continuing execution.
The malware has notable code overlap with Apostle, the Agrius wiper/ransomware family. Multiple reports state that Apostle and IPsec Helper share .NET code characteristics, functions, and execution patterns, and were likely written by the same developer. High-confidence contextual associations in the content tie IPsec Helper to Agrius operations involving exploitation of public-facing applications, ASPXSpy web shells, credential theft, lateral movement, and disruptive activity masquerading as ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom .NET backdoor used by Agrius for persistence, data exfiltration, and deployment of additional malware. It registers itself as a service and appears exclusive to Agrius.
A .NET backdoor with command-and-control functionality (e.g., download and execute payloads) used alongside Apostle; shares significant code overlap with Apostle.
Backdoor/tool capable of running arbitrary PowerShell commands.
Post-exploitation malware registered as a Windows service for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.