NEW: Group Profiler — instant APT intel lookup. Try it →

Agrius

G1030 Iran MITRE ATT&CK →

Also known as: Pink Sandstorm · AMERICIUM · Agonizing Serpens · BlackShadow

Overview

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).

Naming & attribution

Agrius is tracked under 5 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here. Activity attributed since 2020.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Pink SandstormMicrosoft
AMERICIUMMicrosoft
Agonizing SerpensOr Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan
BlackShadowMarc Salinas Fernandez & Jiri Vinopal

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • GALLIUM China — 11 shared techniques (26% overlap)
  • APT5 China — 10 shared techniques (24% overlap)
  • Ember Bear Russia — 13 shared techniques (23% overlap)
  • BlackByte — 12 shared techniques (21% overlap)
  • menuPass China — 12 shared techniques (21% overlap)
  • APT39 Iran — 12 shared techniques (19% overlap)

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 7 attributed custom malware families

TTPs — 22 techniques across 11 tactics

Resource Development

Initial Access

Execution

Persistence

Defense Impairment

Credential Access

Lateral Movement

Exfiltration

Tools & malware (9)

NBTscan · Mimikatz · IPsec Helper · Moneybird · MultiLayer Wiper · DEADWOOD · BFG Agonizer · ASPXSpy · Apostle

Reporting (3)