Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow
22
techniques
9
software
10,446
corpus matches
profile
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).
techniques
22 attributed · most-instrumented first
software
9 malware & tools attributed
Mimikatz
S0002
ASPXSpy
S0073
NBTscan
S0590
IPsec Helper
S1132
Apostle
S1133
DEADWOOD
S1134
MultiLayer Wiper
S1135
BFG Agonizer
S1136
Moneybird
S1137
read this carefully
10,446 corpus matches is not attribution
That count is indicators which exhibit techniques Agrius is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+10 more techniques
showing 30 of 10,446
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.