Agrius — APT Profile
Agrius is an Iran-aligned threat actor tracked since 2020 that runs destructive operations against Israeli and other Middle Eastern organisations. SentinelLabs, which named the group, assessed with medium confidence that it is affiliated with Iran and judged it unlikely to be financially motivated: its apparent ransomware attacks were wipers, including DEADWOOD and Apostle, and the encryption routine was added only later. Agrius consistently hides behind invented extortion personas that pose as criminals or leak-site hacktivists, among them BlackShadow in the 2020 Shirbit breach and Moneybird in 2023, while Unit 42's analysis of the 2023 campaign against Israeli higher-education and technology targets found systematic data theft alongside the wiping. Some reporting connects the group to Iran's Ministry of Intelligence and Security, though Check Point notes its precise affiliation inside Iran has not been established.Also tracked as
Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, UNC2428, SPECTRAL KITTEN
IntelFusions coverage (1)
- MosesStaff Technical Analysis: PyDCrypt Loader and DCSrv Wiper Use DiskCryptor for Ideologically Motivated Destruction Without Ransom 2026-02-16 · Nation-State
Tools & malware
- Apostle Wiper
- ASPXSpy Web Shell
- BFG Agonizer Wiper
- DEADWOOD Wiper
- IPsec Helper Backdoor
- Mimikatz Credential Harvesting
- Moneybird Backdoor
- MultiLayer Wiper Wiper
- NBTscan Network Reconnaissance
Vendor research
- How Microsoft names threat actors Microsoft
- From Wiper to Ransomware: The Evolution of Agrius SentinelOne
- AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS CheckPoint
- Iran turning to cyber-enabled influence operations for greater effect Microsoft
- Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors Unit42