Agrius — APT Profile
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).Also tracked as
Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow
Tools & malware
- Apostle Wiper
- ASPXSpy Web Shell
- BFG Agonizer Wiper
- DEADWOOD Wiper
- IPsec Helper Backdoor
- Mimikatz Credential Harvesting
- Moneybird Backdoor
- MultiLayer Wiper Wiper
- NBTscan Network Reconnaissance
Vendor research
- How Microsoft names threat actors Microsoft
- From Wiper to Ransomware: The Evolution of Agrius SentinelOne
- AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS CheckPoint
- Iran turning to cyber-enabled influence operations for greater effect Microsoft
- Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors Unit42