Agrius Cluster
Suspected state sponsor: Islamic Republic of IranAgrius is an Iranian state-sponsored threat cluster active since at least 2020, widely assessed to operate under Iran's Ministry of Intelligence and Security (MOIS). The group first came to public attention through a series of destructive attacks against Israeli organizations that were initially disguised as ransomware operations. Analysis of the malware and infrastructure revealed that financial gain was never the real objective — the ransomware facade was a cover for pure destruction and data theft.
Targets and Goals
Agrius focuses primarily on Israeli targets, with a particular emphasis on the technology, higher education, healthcare, and insurance sectors. In some campaigns the group has also targeted organizations in the United Arab Emirates and other Middle Eastern countries. The cluster's operations follow a consistent two-stage pattern: first, sensitive data such as personally identifiable information (PII) and intellectual property is stolen and often leaked on Telegram or social media to maximize reputational damage; then, custom wiper malware is deployed to destroy data and disrupt operations.
Tooling and Tactics
Initial access is typically gained by exploiting vulnerabilities in public-facing web servers — including SQL injection and known CVEs in VPN appliances such as FortiOS. After gaining a foothold, the group deploys ASPXSpy-based web shells for persistent access and uses commercial VPN services like ProtonVPN to anonymize its traffic. Tools such as Mimikatz, NBTscan, and Plink are used for credential harvesting and lateral movement. For data destruction, Agrius maintains a growing toolkit of custom wipers including Apostle, DEADWOOD, MultiLayer, PartialWasher, and BFG Agonizer.
Sub-groups and Aliases
The cluster includes several personas and aliases tracked by different vendors: Agonizing Serpens (Unit 42), Pink Sandstorm and AMERICIUM (Microsoft), and BlackShadow — a public-facing persona used to claim attacks and leak stolen data. The sub-group N3TWoRM has been linked to coordinated ransomware campaigns overlapping with Agrius activity in 2021. Microsoft previously tracked an early staging identity as DEV-0227 before formal naming.
observatory results
Most Common Tactics
Targeted Regions
EuropeEurope
May 2021 ~ May 2021
Hong KongHong Kong
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
IranIran
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
IsraelIsrael
Nov 2020 ~ May 2021 Dec 2020 ~ Sep 2021
May 2021 ~ Jul 2021 Apr 2021 ~ May 2021 May 2021 ~ May 2021 Nov 2020 ~ May 2021 Dec 2020 ~ Sep 2021
May 2021 ~ Jul 2021 Dec 2020 ~ Sep 2021
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022 Jan 2023 ~ Nov 2023
May 2023 ~ May 2023 Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Middle EastMiddle East
Nov 2020 ~ May 2021
May 2021 ~ May 2021 Nov 2020 ~ May 2021
PakistanPakistan
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Saudi ArabiaSaudi Arabia
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
South AfricaSouth Africa
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
TurkeyTurkey
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
United Arab EmiratesUnited Arab Emirates
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Recent Activities
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.