Agrius is an Iran-linked threat actor active since at least 2020 and primarily known for targeting organizations in Israel and elsewhere in the Middle East. The group has been assessed with medium confidence as affiliated with Iran and is widely tracked under multiple aliases including Pink Sandstorm, Americium, BlackShadow, Deadwood, Justice Blade, SharpBoys, Spectral Kitten, and Agonizing Serpens. Agrius has conducted both espionage and destructive operations, with a pattern of stealing data from victim environments and then deploying wiper or ransomware-like payloads to disrupt operations and complicate response. The actor is especially notable for using wipers disguised as ransomware. Malware associated with Agrius includes DEADWOOD and Apostle, with Apostle initially functioning as a wiper before later being adapted into operational ransomware. This evolution indicates a disruptive model in which ransomware tradecraft is used primarily for coercion, sabotage, or cover for destructive activity rather than conventional profit-seeking. Agrius has also used the custom .NET backdoor IPsec Helper for persistence, follow-on access, exfiltration, and deployment of additional malware. In later activity, the group used a .NET loader known as Jennlog to decrypt and execute Apostle in memory and was also observed using a Jennlog variant to load OrcusRAT. Operationally, Agrius has exploited public-facing applications for initial access and then deployed ASPXSpy-derived web shells for persistence and remote control. The group has tunneled RDP through web shells and used tools such as Plink and compromised accounts to move laterally inside victim networks. Reported post-compromise behavior includes credential harvesting, use of publicly available offensive tooling, service-based persistence, data collection from databases and critical servers, and exfiltration prior to destructive actions. Agrius has also attempted to impair defenses by modifying security-tool services and using a driver to terminate or remove security software processes. Victimology centers heavily on Israeli organizations, with additional evidence of targeting in the United Arab Emirates and broader Middle Eastern environments. Observed victims and sectors include technology, education, insurance, and other enterprise organizations. The group’s tradecraft and targeting align more closely with state-backed disruptive and espionage objectives than with purely criminal ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices... APT29 has exploited ... CVE-2018-13379 for FortiGate VPNs... Dragonfly ... exploited ... CVE-2018-13379 for Fortinet VPNs... Magic Hound ... exploited ... Fortios SSL VPNs (CVE-2018-13379). Play ... including CVE-2018-13379 ... in FortiOS.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
5 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Mentioned only as a listed actor associated with T1190 in the detection metadata.
Listed as an example threat actor associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Mentioned only as one of many threat actors associated with the Masquerading technique annotation in a Splunk detection entry; no campaign-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.