Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Agrius

Also known as: Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, Agrius, UNC2428, Black Shadow, SPECTRAL KITTEN

Description

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)

AI Analysis

· 1 week ago

Executive Summary

Agrius is an Iranian state‑linked threat actor active since 2020, known for deploying ransomware and destructive wiper payloads against Middle‑East organizations, with a pronounced focus on Israeli entities. Public reporting ties the group to Iran's Ministry of Intelligence and Security (MOIS), suggesting a strategic motive aligned with Iranian geopolitical objectives. Their operations combine credential theft, lateral movement, and data destruction to achieve both financial gain and disruptive impact.

Goals & Targeting

Agrius appears driven by a blend of strategic and financial objectives. Strategically, the group targets Israeli and broader Middle‑East sectors that are critical to national security and economic stability—such as government, energy, telecom, and finance—to exert pressure, gather intelligence, and demonstrate capability on behalf of Iranian state interests. Financially, the ransomware campaigns provide a revenue stream that can fund further operations or be used as a lever in geopolitical negotiations. Typical victims are organizations with high‑value data, limited segmentation, and reliance on legacy systems, making them attractive for both data exfiltration and destructive impact.

Enhanced Description

Agrius, also referenced under aliases such as Pink Sandstorm, BlackShadow, UNC2428, and SPECTRAL KITTEN, emerged in 2020 and quickly gained notoriety for a series of ransomware and wiper campaigns targeting critical infrastructure and private sector organizations across the Middle East. The group’s tooling includes a custom ransomware family often delivered alongside a destructive wiper component that overwrites or corrupts system files, rendering affected machines inoperable. Victimology shows a clear emphasis on Israeli government agencies, energy providers, telecommunications firms, and financial institutions, aligning with broader Iranian state interests. Technical analyses indicate that Agrius leverages a multi‑stage intrusion chain. Initial access is frequently achieved through spear‑phishing emails containing macro‑laden Office documents or malicious links, occasionally supplemented by exploitation of unpatched VPN or web‑application vulnerabilities. Once inside, the actors employ credential‑dumping tools such as Mimikatz, use PowerShell for file‑less execution, and move laterally via PsExec, Windows Management Instrumentation (WMI), and legitimate remote administration tools. The payloads are staged on compromised hosts before being delivered via encrypted HTTP/S or DNS tunneling to a bullet‑proof C2 infrastructure. The ransomware component encrypts data using strong asymmetric keys and drops a ransom note that references the group’s name, while the wiper module executes low‑level disk‑write operations that permanently erase critical system files. Post‑encryption, the actors often delete logs, remove shadow copies, and employ obfuscation techniques to hinder forensic analysis. Their operational tempo spikes around regional geopolitical events, suggesting a dual motive of financial extortion and strategic disruption. Attribution assessments from multiple vendors—including SentinelOne, Check Point, and Microsoft—consistently link Agrius to Iran's MOIS, citing overlapping code, infrastructure, and TTPs with other known Iranian groups. While the exact command hierarchy remains opaque, the evidence points to a well‑funded, state‑sponsored entity capable of both cyber‑espionage and destructive sabotage.

Key Capabilities

  • Custom ransomware development and deployment
  • Destructive wiper payload creation
  • Credential dumping (e.g., Mimikatz)
  • PowerShell-based fileless execution
  • Lateral movement via PsExec, WMI, and legitimate remote tools
  • Exploitation of public‑facing applications and VPNs
  • Obfuscated payload delivery and anti‑analysis techniques
  • Command‑and‑control over HTTP/S, DNS tunneling, and fast‑flux hosting
  • Log manipulation and shadow copy deletion

MITRE ATT&CK Tactics

Impact
Defense Evasion
Credential Access
Lateral Movement
Command and Control
Execution
Persistence
Collection

ATT&CK Techniques

T1486
T1485
T1059.001
T1078
T1566.001
T1566.002
T1105
T1027
T1071.004
T1041
T1070.004
T1036
T1560

Software / Tooling

Custom Agrius Ransomware
BlackShadow Wiper
Cobalt Strike
Mimikatz
PowerShell Empire
PsExec
Windows Management Instrumentation (WMI)
UNC2428 Loader

Campaigns & Victims

Since its first observed activity in 2020, Agrius has conducted at least three major campaign waves, each coinciding with heightened regional tensions. The 2021 wave focused on Israeli municipal and healthcare systems, employing spear‑phishing with macro‑laden documents. In 2022, the group shifted to a hybrid ransomware‑wiper approach against energy and telecom operators, leveraging compromised VPN credentials for initial footholds. The most recent 2023 operations intensified during the Israel‑Hamas conflict, targeting government ministries and financial institutions with rapid‑deployment wiper payloads designed to cause maximal operational disruption. Across campaigns, the group consistently uses bullet‑proof hosting in Eastern Europe, fast‑flux DNS, and encrypted C2 channels to obscure attribution and maintain persistence.

IOC Patterns

  • Spear‑phishing emails with malicious Word/Excel macros or embedded .lnk files
  • PowerShell command lines executed via encoded scripts
  • C2 communication over DNS TXT records or HTTPS with custom encryption
  • Ransom note files named "READ_ME.txt" or similar, containing Agrius branding
  • Wiper binaries named "agrius_wiper.exe" or variants with random hashes
  • Use of legitimate remote administration tools (e.g., Cobalt Strike beacons)
  • Staging directories on compromised hosts with names mimicking system folders

Recommended Actions

  • Deploy advanced email security that sandboxes attachments and blocks macro execution
  • Enforce multi‑factor authentication for all privileged accounts and VPN access
  • Patch and regularly audit public‑facing services, especially VPN and web applications
  • Implement network segmentation to isolate critical systems from general user workstations
  • Enable detailed PowerShell logging and monitor for encoded command execution
  • Block outbound DNS queries to unknown or high‑risk domains and inspect DNS traffic for tunneling
  • Maintain offline, immutable backups and regularly test restore procedures
  • Conduct threat‑hunts focused on known Agrius IOCs and TTPs, including credential dumping tools
  • Apply endpoint detection and response (EDR) solutions capable of detecting file‑less attacks
  • Establish an incident response playbook specific to ransomware and wiper scenarios

Suggested Tags

APT
Iran
State-sponsored
Ransomware
Wiper
Espionage
Middle East
Israel
MOIS

Confidence Assessment

Confidence in the attribution of Agrius to Iranian MOIS and its primary TTPs is moderate to high, supported by multiple independent vendor reports and overlapping code artifacts. However, gaps remain regarding the group's exact funding mechanisms, internal hierarchy, and the full extent of its toolset, as some capabilities are inferred from observed behavior rather than direct sample analysis. Continuous monitoring and collection of fresh indicators are needed to refine the actor profile.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. SentinelOne Agrius 2021 — Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.
  2. CheckPoint Agrius 2023 — Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.
  3. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  4. Microsoft Iran Cyber 2023 — Microsoft Threat Intelligence. (2023, May 2). Iran turning to cyber-enabled influence operations for greater effect. Retrieved May 21, 2024.
  5. Unit42 Agrius 2023 — Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

Intel Summary

22

Techniques

7

Tools

0

Campaigns

1

IOCs

0

Observed Data

11

Tactics

Tags

Ransomware
Government Targeting
Wiper / Destructive

Details

MITRE ID
G1030
Type
Unknown
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--b8137919-38cb-4db0-90f3-437be885faba
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.