IPsec Helper can identify specific files and folders for follow-on exfiltration.2
tool
IPsec Helper S1132
- Type
- malware
- Platform
- Windows
- Created
- 22 May 2024
- Last modified
- 29 August 2024
IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1132
IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution.3
IPsec Helper exfiltrates specific files through its command and control framework.4
IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node.5
IPsec Helper can run arbitrary PowerShell commands passed to it.6
IPsec Helper can run arbitrary commands passed to it through cmd.exe.7
Standing S1132
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
66th percentile · 66% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
89th percentile · 89% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
71st percentile · 71% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S1132
759 distinct rules cover the 15 techniques recorded for this tool. The 800 technique-to-rule mappings resolve to 759 distinct rules, because one rule can cover several techniques. 527 Sigma · 232 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org