Agrius
Also known as: Pink Sandstorm · AMERICIUM · Agonizing Serpens · BlackShadow
Overview
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).
Naming & attribution
Agrius is tracked under 5 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here. Activity attributed since 2020.
| Name | First reported by |
|---|---|
| Pink Sandstorm | Microsoft |
| AMERICIUM | Microsoft |
| Agonizing Serpens | Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan |
| BlackShadow | Marc Salinas Fernandez & Jiri Vinopal |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- GALLIUM China — 11 shared techniques (26% overlap)
- APT5 China — 10 shared techniques (24% overlap)
- Ember Bear Russia — 13 shared techniques (23% overlap)
- BlackByte — 12 shared techniques (21% overlap)
- menuPass China — 12 shared techniques (21% overlap)
- APT39 Iran — 12 shared techniques (19% overlap)
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 7 attributed custom malware families
TTPs — 22 techniques across 11 tactics
Resource Development
-
T1583Acquire Infrastructure
Initial Access
Execution
-
T1059.003Windows Command Shell
Persistence
-
T1505.003Web Shell -
T1543.003Windows Service
Stealth
-
T1036Masquerading -
T1078.002Domain Accounts -
T1140Deobfuscate/Decode Files or Information
Defense Impairment
-
T1685Disable or Modify Tools
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager -
T1110Brute Force -
T1110.003Password Spraying
Discovery
-
T1018Remote System Discovery -
T1046Network Service Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1570Lateral Tool Transfer
Collection
-
T1005Data from Local System -
T1074.001Local Data Staging -
T1119Automated Collection -
T1560.001Archive via Utility
Exfiltration
Tools & malware (9)
NBTscan · Mimikatz · IPsec Helper · Moneybird · MultiLayer Wiper · DEADWOOD · BFG Agonizer · ASPXSpy · Apostle
Reporting (3)
- Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors — Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan
- How Microsoft names threat actors — Microsoft
- AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS — Marc Salinas Fernandez & Jiri Vinopal