Agrius is an Iran-linked threat actor conducting destructive cyber operations, primarily against Israeli organizations, with activity observed since 2020. It is also tracked as Agonizing Serpens, Pink Sandstorm, Americium, BlackShadow, Justice Blade, SharpBoys, and Spectral Kitten. Its targets include technology companies, educational institutions, and insurance organizations. Although its early operations included espionage, its principal operational focus is disruption and destruction, including wiper attacks disguised as financially motivated ransomware incidents. Agrius exploits public-facing applications to gain access and deploys variants of the ASPXSpy webshell. It uses VPN services to obscure its activity, compromised accounts and tunneled RDP connections for lateral movement, and publicly available offensive tools for credential harvesting. Its custom .NET backdoor, IPsec Helper, establishes persistence as a Windows service and supports data exfiltration and deployment of additional malware. The group has used Base64-encoded webshell variants to evade detection. Its destructive malware includes DEADWOOD, also known as Detbosit, and Apostle, which evolved from a wiper into functional ransomware. Agonizing Serpens operations have also used the MultiLayer and PartialWasher wipers against Israeli technology and education organizations. Activity associated with the BlackShadow alias includes theft and disclosure of data from the Israeli insurer Shirbit. Agrius's ransomware use is associated primarily with disruptive effects rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.
Listed under vulnerabilities used by Black Shadow: a Fortinet FortiGate SSLVPN vulnerability allowing unauthorized access to files on the appliance.
Listed under vulnerabilities used by Black Shadow: a vulnerability in Microsoft Exchange mail servers allowing remote code execution.
Listed under vulnerabilities used by Black Shadow: a vulnerability enabling remote code execution through SMBv3 on Windows servers.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
15 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in technique annotations. The content does not attribute ResetNightmare exploitation or a specific campaign to this group.
Referenced only as an annotated actor associated with the detection technique.
Mentioned as a comparison to Screening Serpens: a destructive Iranian cluster reported to deploy wiper malware against Israeli education and technology organizations.
Agrius appears only in the detection's annotations list.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.