Agrius — APT Profile

Agrius is an Iran-aligned threat actor tracked since 2020 that runs destructive operations against Israeli and other Middle Eastern organisations. SentinelLabs, which named the group, assessed with medium confidence that it is affiliated with Iran and judged it unlikely to be financially motivated: its apparent ransomware attacks were wipers, including DEADWOOD and Apostle, and the encryption routine was added only later. Agrius consistently hides behind invented extortion personas that pose as criminals or leak-site hacktivists, among them BlackShadow in the 2020 Shirbit breach and Moneybird in 2023, while Unit 42's analysis of the 2023 campaign against Israeli higher-education and technology targets found systematic data theft alongside the wiping. Some reporting connects the group to Iran's Ministry of Intelligence and Security, though Check Point notes its precise affiliation inside Iran has not been established.

Also tracked as

Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, UNC2428, SPECTRAL KITTEN

IntelFusions coverage (1)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions