Agrius
Named by SentinelOneSuspected state sponsor: Islamic Republic of IranAgrius is an Iranian state-linked threat actor active since at least 2020, assessed by multiple vendors to operate on behalf of Iran's Ministry of Intelligence and Security (MOIS). The group is best known for destructive wiper and fake-ransomware campaigns aimed primarily at Israeli organizations across the technology, education, insurance, and healthcare sectors. Agrius gains initial access by exploiting public-facing web applications, deploys ASPXSpy-based web shells for persistence, and ultimately delivers custom wipers such as Apostle and DEADWOOD to destroy data and disrupt operations. Microsoft tracks the same cluster as Pink Sandstorm and AMERICIUM.
Targeted Regions
Hong KongHong Kong
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
IranIran
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
IsraelIsrael
Nov 2020 ~ May 2021 Dec 2020 ~ Sep 2021
Nov 2020 ~ May 2021 Dec 2020 ~ Sep 2021
Dec 2020 ~ Sep 2021
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
May 2023 ~ May 2023
Middle EastMiddle East
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
PakistanPakistan
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Saudi ArabiaSaudi Arabia
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
South AfricaSouth Africa
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
TurkeyTurkey
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
United Arab EmiratesUnited Arab Emirates
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.