IPsec Helper is a custom .NET backdoor associated with the Iran-linked threat actor Agrius and used in post-compromise operations against organizations in the Middle East, particularly Israeli targets. It has been deployed alongside Agrius destructive tooling, including Apostle and DEADWOOD, and appears to share code characteristics and development patterns with Apostle, suggesting common authorship. The malware is typically installed as a Windows service to establish persistence and operate covertly on selected hosts after initial access has already been obtained through other means such as exploitation of public-facing applications and web shell deployment.
Functionally, IPsec Helper provides remote backdoor access for follow-on operations. Reported capabilities include executing arbitrary PowerShell commands, running Visual Basic scripts and other attacker-supplied commands, exfiltrating selected files through its command-and-control channel, modifying registry keys based on operator input, and deleting registry artifacts related to its own execution and use. It has also been described as capable of supporting deployment of additional malware. The malware incorporates delayed execution behavior by sleeping in repeated randomized intervals before continuing, consistent with sandbox-evasion or anti-analysis tradecraft.
Operationally, IPsec Helper has been used as part of Agrius intrusions that combined espionage, data theft, and destructive activity masquerading as ransomware. Its role is best characterized as a persistent post-exploitation backdoor used to maintain access, execute commands, and facilitate exfiltration or staging for subsequent payloads on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A report about Agrius attacks mentions a custom .NET backdoor called IPsec Helper.
Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom .NET backdoor used by Agrius for persistence, data exfiltration, and deployment of additional malware. It registers itself as a service and appears exclusive to Agrius.
A .NET backdoor with command-and-control functionality (e.g., download and execute payloads) used alongside Apostle; shares significant code overlap with Apostle.
Backdoor/tool capable of running arbitrary PowerShell commands.
A custom .NET backdoor associated in the report with Agrius; mentioned for code-style, naming, encryption, and infrastructure similarities to ShellClient.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.