Also known as: Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, Agrius, UNC2428, Black Shadow, SPECTRAL KITTEN
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)
Executive Summary
Agrius is an Iranian state‑linked threat actor active since 2020, known for deploying ransomware and destructive wiper payloads against Middle‑East organizations, with a pronounced focus on Israeli entities. Public reporting ties the group to Iran's Ministry of Intelligence and Security (MOIS), suggesting a strategic motive aligned with Iranian geopolitical objectives. Their operations combine credential theft, lateral movement, and data destruction to achieve both financial gain and disruptive impact.
Goals & Targeting
Agrius appears driven by a blend of strategic and financial objectives. Strategically, the group targets Israeli and broader Middle‑East sectors that are critical to national security and economic stability—such as government, energy, telecom, and finance—to exert pressure, gather intelligence, and demonstrate capability on behalf of Iranian state interests. Financially, the ransomware campaigns provide a revenue stream that can fund further operations or be used as a lever in geopolitical negotiations. Typical victims are organizations with high‑value data, limited segmentation, and reliance on legacy systems, making them attractive for both data exfiltration and destructive impact.
Enhanced Description
Agrius, also referenced under aliases such as Pink Sandstorm, BlackShadow, UNC2428, and SPECTRAL KITTEN, emerged in 2020 and quickly gained notoriety for a series of ransomware and wiper campaigns targeting critical infrastructure and private sector organizations across the Middle East. The group’s tooling includes a custom ransomware family often delivered alongside a destructive wiper component that overwrites or corrupts system files, rendering affected machines inoperable. Victimology shows a clear emphasis on Israeli government agencies, energy providers, telecommunications firms, and financial institutions, aligning with broader Iranian state interests. Technical analyses indicate that Agrius leverages a multi‑stage intrusion chain. Initial access is frequently achieved through spear‑phishing emails containing macro‑laden Office documents or malicious links, occasionally supplemented by exploitation of unpatched VPN or web‑application vulnerabilities. Once inside, the actors employ credential‑dumping tools such as Mimikatz, use PowerShell for file‑less execution, and move laterally via PsExec, Windows Management Instrumentation (WMI), and legitimate remote administration tools. The payloads are staged on compromised hosts before being delivered via encrypted HTTP/S or DNS tunneling to a bullet‑proof C2 infrastructure. The ransomware component encrypts data using strong asymmetric keys and drops a ransom note that references the group’s name, while the wiper module executes low‑level disk‑write operations that permanently erase critical system files. Post‑encryption, the actors often delete logs, remove shadow copies, and employ obfuscation techniques to hinder forensic analysis. Their operational tempo spikes around regional geopolitical events, suggesting a dual motive of financial extortion and strategic disruption. Attribution assessments from multiple vendors—including SentinelOne, Check Point, and Microsoft—consistently link Agrius to Iran's MOIS, citing overlapping code, infrastructure, and TTPs with other known Iranian groups. While the exact command hierarchy remains opaque, the evidence points to a well‑funded, state‑sponsored entity capable of both cyber‑espionage and destructive sabotage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first observed activity in 2020, Agrius has conducted at least three major campaign waves, each coinciding with heightened regional tensions. The 2021 wave focused on Israeli municipal and healthcare systems, employing spear‑phishing with macro‑laden documents. In 2022, the group shifted to a hybrid ransomware‑wiper approach against energy and telecom operators, leveraging compromised VPN credentials for initial footholds. The most recent 2023 operations intensified during the Israel‑Hamas conflict, targeting government ministries and financial institutions with rapid‑deployment wiper payloads designed to cause maximal operational disruption. Across campaigns, the group consistently uses bullet‑proof hosting in Eastern Europe, fast‑flux DNS, and encrypted C2 channels to obscure attribution and maintain persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the attribution of Agrius to Iranian MOIS and its primary TTPs is moderate to high, supported by multiple independent vendor reports and overlapping code artifacts. However, gaps remain regarding the group's exact funding mechanisms, internal hierarchy, and the full extent of its toolset, as some capabilities are inferred from observed behavior rather than direct sample analysis. Continuous monitoring and collection of fresh indicators are needed to refine the actor profile.
No campaigns linked yet.
No observed data linked yet.
22
Techniques
7
Tools
0
Campaigns
1
IOCs
0
Observed Data
11
Tactics