ESET reported that the Iran-aligned Agrius threat group deployed a previously undocumented wiper dubbed Fantasy through a software supply-chain compromise. The operation abused a legitimate Israeli software distributor’s update mechanism to deliver malware to downstream targets, allowing the attackers to masquerade as trusted software and gain access inside victim environments before launching destructive activity.
According to ESET’s findings, Fantasy was designed to wipe systems while presenting itself as ransomware, continuing Agrius’s pattern of disruptive attacks that blend espionage-style intrusion with destructive payloads. The campaign targeted organizations in Israel, and the use of a compromised supplier highlighted how trusted third-party software channels can be weaponized to bypass defenses and spread malware deeper into enterprise networks.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
ESET published research detailing the new Fantasy wiper and attributing the supply-chain attack to Agrius, describing the malware and the intrusion chain used to target Israeli organizations.
After compromising the supplier, Agrius delivered a new wiper dubbed Fantasy to selected victims through a software update mechanism. The malware was used in attacks against organizations in Israel.
ESET reported that the Iran-aligned Agrius group breached an Israeli software company as part of a supply-chain operation, using the supplier's software distribution channel to reach downstream targets.
SentinelLabs published research on Agrius describing the group's evolution from destructive wiper attacks to ransomware-style operations. The report documented an earlier phase of Agrius activity that predates the later Fantasy supply-chain campaign in Israel.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcesentinelone.com
Open sourceeset.com
Open sourcecommunity.riskiq.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.