Moneybird is a C++ ransomware family associated with intrusions against Israeli organizations and assessed to bear the hallmarks of the Iran-linked threat group Agrius, also known as BlackShadow. It appears to be a newer ransomware tool in Agrius operations, following the group’s earlier use of Apostle and its history of disruptive ransomware and wiper activity.
Moneybird is designed to encrypt selected victim files rather than indiscriminately processing all accessible data. Reported behavior indicates the malware uses targeted paths and skips most files outside its intended scope. It targets common high-value file types such as documents, certificates, and database files while avoiding executables, shared libraries, and similar system-critical items. The malware also contains an embedded configuration blob that supports its execution logic.
Observed Moneybird intrusions involved compromise of public-facing web servers for initial access, followed by deployment of ASPXSPY webshell variants, internal reconnaissance, lateral movement, and data exfiltration before ransomware execution. This tradecraft aligns with broader Linux and server-focused ransomware operations that prioritize organizational disruption and extortion over mass consumer targeting. In the reported cases, the victims were Israeli organizations, consistent with Agrius’s established targeting patterns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to Check Point investigators, Moneybird is a new product for the group. Most of its previous attacks have been carried out with ransomware called Apostle.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned only as an example of a crypto library choice.
A new C++ ransomware used by the Iran-linked Agrius group against Israeli organizations. It is deployed after intrusion via public-facing web servers and ASPXSPY variants, followed by lateral movement, reconnaissance, and data exfiltration. It uses targeted paths to skip most files on the victim network.
Contains an embedded configuration blob within the malware.
Ransomware that selectively encrypts common data file types while avoiding executables and libraries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.