Actors Insights|Latest update30/07/2026

Agonizing Serpens

Named by Palo AltoSuspected state sponsor: Islamic Republic of Iran

Agonizing Serpens is the name assigned by Palo Alto Networks Unit 42 to an Iranian-linked threat actor widely known as Agrius. The group has been active since 2020 and is recognized for combining data theft with destructive wiper attacks against Israeli organizations, particularly in the technology and higher education sectors. In campaigns documented through 2023, the actor stole personally identifiable information and intellectual property before deploying novel wipers — including BFG Agonizer, MultiLayer, and PartialWasher — to destroy endpoints and cover its tracks. The group actively invests in bypassing endpoint detection and response tools.

First Seen:Jan 2023
Last Seen:Nov 2023
Indexed Reports:1
Public IOCs:28
Cluster: AgriusMitre: AgriusMisp: Pink Sandstorm
also known as:
AMERICIUM (Microsoft)BlackShadow (Kaspersky)DEV-0022Agrius (SentinelOne)Agonizing Serpens (Palo Alto)UNC2428SPECTRAL KITTENPink Sandstorm (Microsoft)G1030 (Mitre)

Targeted Regions

Israel
IL
Israel
Israel
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023Nov 2026

Targeted Sectors

Information TechnologyEducation

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.