Fantasy is a destructive malware family associated with the Iran-aligned Agrius threat group. It is best known as a wiper used in a 2022 supply-chain intrusion in which a trusted Israeli software developer was compromised and downstream victims in multiple sectors were impacted, including organizations beyond Israel. Fantasy has also been referenced in a separate context as the name of a shellcode-based deployment component used to install Goldbackdoor in an APT37 campaign against journalists, where it functioned as one of two stealthy process-injection mechanisms. Because the same name has been used for distinct malicious components in different operations, attribution and classification should be handled carefully by context.
In the Agrius activity, Fantasy is characterized as a destructive payload deployed after initial compromise, consistent with the group’s broader use of disruptive malware in retaliation-oriented operations. Its operational role was sabotage rather than monetization, and its use in a software supply-chain compromise marked an escalation in Agrius tradecraft by leveraging trusted third-party access to reach multiple downstream environments. Fantasy is part of a broader cluster of Iranian disruptive tooling that includes Apostle and later cross-platform wipers used against enterprise targets.
In the APT37 reporting, Fantasy refers to a shellcode payload retrieved during a spearphishing-driven infection chain targeting journalists covering North Korea. In that operation, the payload was used to deploy Goldbackdoor through stealthy process injection after execution of a malicious shortcut and PowerShell stages. That Fantasy component served as a loader or deployment mechanism rather than the primary espionage backdoor itself.
Given the supplied facts, the strongest high-confidence identification for Fantasy as a named malware entry is the Agrius-associated wiper used in supply-chain attacks, while noting that the same label has also been applied to a Goldbackdoor deployment payload in unrelated North Korean espionage activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This payload is called “Fantasy,” and according to Stairwell, it’s the first of the two deploying mechanisms of Goldbackdoor, both relying on stealthy process injection.
Supply chain exploitation: The deployment of the Fantasy wiper represented a significant escalation in Agrius’s targeting methodology. By compromising a trusted third-party Israeli software developer, the threat actors executed a supply-chain attack that impacted downstream victims across multiple global verticals.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The second script downloads and executes a shellcode payload stored on Microsoft OneDrive, a legitimate cloud-based file hosting service... The malware utilizes legitimate cloud services for the exfiltration of files, with Stairwell noticing the abuse of both Google Drive and Microsoft OneDrive.
Upon execution, a PowerShell script launches... The second script downloads and executes a shellcode payload stored on Microsoft OneDrive
Upon execution, a PowerShell script launches and opens a decoy document (doc) for distraction while decoding a second script in the background.
The second script downloads and executes a shellcode payload stored on Microsoft OneDrive, a legitimate cloud-based file hosting service... The malware utilizes legitimate cloud services for the exfiltration of files, with Stairwell noticing the abuse of both Google Drive and Microsoft OneDrive.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A wiper used in a supply-chain attack after compromise of a trusted third-party software developer, impacting downstream victims across multiple sectors.
A destructive wiper used in a supply-chain attack to damage targets across multiple sectors beyond Israel.
Named wiper malware included in the IOC list as part of the destructive malware set discussed.
A shellcode payload used as a deployment mechanism for Goldbackdoor, downloaded from Microsoft OneDrive and executed via stealthy process injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.