Agrius

MITRE ATT&CK: G1030 View on attack.mitre.org

Aliases: Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, Agrius, UNC2428, Black Shadow, SPECTRAL KITTEN, Deadwood, SharpBoys, DEV-0227, FireAnt, Justice Blade

First seen
2020-01-01 00:00:00
Origin
IR
Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:13:06

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:il

Context

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).

Detection coverage

  • 13 YARA rules
  • 561 Sigma rules

Malware & tools used

  • Remote System Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Web Shell (attack-pattern)
  • Data from Local System (attack-pattern)
  • Acquire Infrastructure (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Password Spraying (attack-pattern)
  • Automated Collection (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Masquerading (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Brute Force (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Windows Service (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Moneybird (malware)
  • Apostle (malware)
  • ASPXSpy (malware)

Reports & references

  • oodaloop.com — Critical Infrastructure Remains The Brass Ring For Cyber Attackers In 2024 (report)
  • Palo Alto Unit 42 — Agonizing Serpens Targets Israeli Tech Higher Ed Sectors (report)
  • socprime.com — Agonizing Serpens Attack Detection Iran Backed Hackers Target Israeli Tech Firms And Educational Institutions (report)
  • therecord.media — Iran Linked Hackers Target Israel Education Tech Sectors (report)
  • enigmasoftware.com — Moneybirdransomware Removal (report)
  • research.checkpoint.com — Agrius Deploys Moneybird In Targeted Attacks Against Israeli Organizations (report)
  • services.google.com — M Trends 2025 En (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • assets.sentinelone.com — Evol Agrius (report)
  • MITRE ATT&CK — G1030 (report)
  • Microsoft — Iran Turning To Cyber Enabled Influence Operations For Greater Effect 05022023 (report)

External references