THREAT_ACTOR · G1030
Agrius
Also known as: Agrius, Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow
Profile
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).
MITRE ATT&CK ↗Techniques
22 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1003.002 Security Account ManagerT1005 Data from Local SystemT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1036 MasqueradingT1041 Exfiltration Over C2 ChannelT1046 Network Service DiscoveryT1059.003 Windows Command ShellT1074.001 Local Data StagingT1078.002 Domain AccountsT1110 Brute ForceT1110.003 Password SprayingT1119 Automated CollectionT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1505.003 Web ShellT1543.003 Windows ServiceT1560.001 Archive via UtilityT1570 Lateral Tool TransferT1583 Acquire InfrastructureT1685 Disable or Modify Tools
Software
9 malware/tools attributed to this actor.
MimikatzASPXSpyNBTscanIPsec HelperApostleDEADWOODMultiLayer WiperBFG AgonizerMoneybird
Related corpus activity
9,251 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Agrius.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,251.