BFG Agonizer is a Windows wiper associated with Iranian disruptive operations, particularly activity linked to Agonizing Serpens (Agrius) and collaborative deployments with Boggy Serpens (MuddyWater). It is part of a broader Iranian arsenal of destructive malware used in campaigns targeting Israeli organizations and other regional adversaries. Operations involving BFG Agonizer have been described as using legitimate remote monitoring and management tooling to distribute the payload at scale.
The malware is designed to render systems unbootable and inhibit recovery. Its core destructive behavior includes opening the primary physical drive and wiping the boot sector, preventing normal startup and complicating remediation. It also uses elevated privileges to invoke a hard-error condition that forces a blue-screen crash; after shutdown, affected systems are left non-bootable.
BFG Agonizer also incorporates defense-evasion features uncommon in simpler wipers. It performs DLL unhooking and import address table unhooking to remove user-mode hooks commonly placed by security products, reducing visibility into its execution and interfering with endpoint defenses. These traits indicate deliberate preparation for execution in monitored enterprise environments.
Overall, BFG Agonizer is a destructive malware family focused on impact rather than persistence or monetization. Its combination of boot-sector wiping, forced system crash behavior, and user-mode unhooking makes it a purpose-built wiper intended to maximize operational disruption on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MultiLayer and BFG Agonizer: Concurrently, collaborative deployments between Agonizing Serpens and Boggy Serpens (aka MuddyWater) introduced highly modular wipers like MultiLayer and BFG Agonizer. These operations frequently abused legitimate remote monitoring and management (RMM) tools to distribute the payloads at scale.
MultiLayer and BFG Agonizer: Concurrently, collaborative deployments between Agonizing Serpens and Boggy Serpens (aka MuddyWater) introduced highly modular wipers like MultiLayer and BFG Agonizer. These operations frequently abused legitimate remote monitoring and management (RMM) tools to distribute the payloads at scale.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a wiper targeting Israel.
A highly modular wiper used in collaborative operations and distributed through abused legitimate RMM tools.
Destructive wiper malware family referenced as part of Iran-aligned wiper tooling.
Wiper malware that destroys the boot sector to inhibit system recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.