N3TWoRM
Named by self givenSuspected state sponsor: Islamic Republic of IranN3TWoRM is a ransomware persona linked to the Iranian Agrius cluster that emerged in April 2021 during a wave of cyberattacks against Israeli organizations. Rather than seeking financial ransom, the group used ransomware as a disruptive tool consistent with Iranian state-aligned objectives. Researchers noted connections to the 2020 Pay2Key attacks and assessed that N3TWoRM's campaigns may have been coordinated with concurrent Agrius wiper activity as part of a broader Iranian strategy targeting Israel. Activity attributed to this persona was short-lived, with operations concentrated between April and July 2021.
Targeted Regions
EuropeEurope
May 2021 ~ May 2021
IsraelIsrael
May 2021 ~ Jul 2021 Apr 2021 ~ May 2021 May 2021 ~ May 2021
May 2021 ~ Jul 2021
Middle EastMiddle East
May 2021 ~ May 2021
Targeted Sectors
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.