Agrius
MITRE ATT&CK: G1030 View on attack.mitre.org
Aliases: Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, Agrius, UNC2428, Black Shadow, SPECTRAL KITTEN, Deadwood, SharpBoys, DEV-0227, FireAnt, Justice Blade
- First seen
- 2020-01-01 00:00:00
- Origin
- IR
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:13:06
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities
Targeted regions: country_code:il
Context
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).
Detection coverage
- 13 YARA rules
- 561 Sigma rules
Malware & tools used
- Remote System Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Network Service Discovery (attack-pattern)
- Domain Accounts (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Web Shell (attack-pattern)
- Data from Local System (attack-pattern)
- Acquire Infrastructure (attack-pattern)
- Local Data Staging (attack-pattern)
- Password Spraying (attack-pattern)
- Automated Collection (attack-pattern)
- Security Account Manager (attack-pattern)
- Archive via Utility (attack-pattern)
- Masquerading (attack-pattern)
- LSASS Memory (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Brute Force (attack-pattern)
- Windows Command Shell (attack-pattern)
- Windows Service (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Moneybird (malware)
- Apostle (malware)
- ASPXSpy (malware)
Reports & references
- oodaloop.com — Critical Infrastructure Remains The Brass Ring For Cyber Attackers In 2024 (report)
- Palo Alto Unit 42 — Agonizing Serpens Targets Israeli Tech Higher Ed Sectors (report)
- socprime.com — Agonizing Serpens Attack Detection Iran Backed Hackers Target Israeli Tech Firms And Educational Institutions (report)
- therecord.media — Iran Linked Hackers Target Israel Education Tech Sectors (report)
- enigmasoftware.com — Moneybirdransomware Removal (report)
- research.checkpoint.com — Agrius Deploys Moneybird In Targeted Attacks Against Israeli Organizations (report)
- services.google.com — M Trends 2025 En (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- assets.sentinelone.com — Evol Agrius (report)
- MITRE ATT&CK — G1030 (report)
- Microsoft — Iran Turning To Cyber Enabled Influence Operations For Greater Effect 05022023 (report)
External references
- mitre-attack — G1030
- BlackShadow
- Pink Sandstorm
- AMERICIUM
- Agonizing Serpens
- SentinelOne Agrius 2021
- CheckPoint Agrius 2023
- Microsoft Threat Actor Naming July 2023
- Microsoft Iran Cyber 2023
- Unit42 Agrius 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy