Agrius is an Iran-linked threat actor, also known as Agonizing Serpens, Pink Sandstorm, Americium, BlackShadow, Deadwood, Justice Blade, SharpBoys, and Spectral Kitten. Active since at least 2020, it has conducted espionage and destructive operations principally against Israeli organizations and other Middle Eastern targets. The group has targeted technology and educational organizations and is associated with activity against a critical nation-owned facility in the United Arab Emirates. Agrius is characterized by destructive operations in which wiper malware is presented as ransomware to create punitive or coercive effects rather than to generate revenue. It has used the DEADWOOD wiper and Apostle, a .NET malware family that evolved from a wiper into functional ransomware. The group likely retains a sabotage-oriented mission despite Apostle’s ransomware functionality. The actor has compromised public-facing applications, deployed ASPXSpy-derived web shells, and used victim VPN access for post-compromise operations. Its web shells have supported RDP tunneling and lateral movement using compromised accounts. Agrius has also used public offensive-security tooling for credential harvesting and lateral movement, collected data from databases and critical servers, and employed wiping for anti-forensic purposes. Its custom .NET backdoor IPsec Helper has been deployed selectively for persistence, data exfiltration, and delivery of additional payloads; it establishes persistence through a Windows service. Agrius has additionally impaired defenses by modifying EDR-related services and using a kernel driver to stop or remove security-product processes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices... APT29 has exploited ... CVE-2018-13379 for FortiGate VPNs... Dragonfly ... exploited ... CVE-2018-13379 for Fortinet VPNs... Magic Hound ... exploited ... Fortios SSL VPNs (CVE-2018-13379). Play ... including CVE-2018-13379 ... in FortiOS.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
5 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison to Screening Serpens: a destructive Iranian cluster reported to deploy wiper malware against Israeli education and technology organizations.
Agrius appears only in the detection's annotations list.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Mentioned only as a listed actor associated with T1190 in the detection metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.