Actors Insights|Latest update30/07/2026

N3TWoRM

Named by self givenSuspected state sponsor: Islamic Republic of Iran

N3TWoRM is a ransomware persona linked to the Iranian Agrius cluster that emerged in April 2021 during a wave of cyberattacks against Israeli organizations. Rather than seeking financial ransom, the group used ransomware as a disruptive tool consistent with Iranian state-aligned objectives. Researchers noted connections to the 2020 Pay2Key attacks and assessed that N3TWoRM's campaigns may have been coordinated with concurrent Agrius wiper activity as part of a broader Iranian strategy targeting Israel. Activity attributed to this persona was short-lived, with operations concentrated between April and July 2021.

First Seen:Apr 2021
Last Seen:Jul 2021
Indexed Reports:4
Public IOCs:4
Cluster: Agrius
also known as:
N3TWoRM (self given)

Targeted Regions

Europe
EU
Europe
Europe
May 2021 ~ May 2021
Israel
IL
Israel
Israel
May 2021 ~ Jul 2021
Apr 2021 ~ May 2021
May 2021 ~ May 2021
May 2021 ~ Jul 2021
Middle East
ME
Middle East
Middle East
May 2021 ~ May 2021
Jan 2021Oct 2026

Targeted Sectors

LogisticsRetailConsultingHuman Rights

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.