Actors Insights|Latest update30/07/2026

Agrius Cluster

Suspected state sponsor: Islamic Republic of Iran

Agrius is an Iranian state-sponsored threat cluster active since at least 2020, widely assessed to operate under Iran's Ministry of Intelligence and Security (MOIS). The group first came to public attention through a series of destructive attacks against Israeli organizations that were initially disguised as ransomware operations. Analysis of the malware and infrastructure revealed that financial gain was never the real objective — the ransomware facade was a cover for pure destruction and data theft.

 

Targets and Goals

Agrius focuses primarily on Israeli targets, with a particular emphasis on the technology, higher education, healthcare, and insurance sectors. In some campaigns the group has also targeted organizations in the United Arab Emirates and other Middle Eastern countries. The cluster's operations follow a consistent two-stage pattern: first, sensitive data such as personally identifiable information (PII) and intellectual property is stolen and often leaked on Telegram or social media to maximize reputational damage; then, custom wiper malware is deployed to destroy data and disrupt operations.

 

Tooling and Tactics

Initial access is typically gained by exploiting vulnerabilities in public-facing web servers — including SQL injection and known CVEs in VPN appliances such as FortiOS. After gaining a foothold, the group deploys ASPXSpy-based web shells for persistent access and uses commercial VPN services like ProtonVPN to anonymize its traffic. Tools such as Mimikatz, NBTscan, and Plink are used for credential harvesting and lateral movement. For data destruction, Agrius maintains a growing toolkit of custom wipers including Apostle, DEADWOOD, MultiLayer, PartialWasher, and BFG Agonizer.

 

Sub-groups and Aliases

The cluster includes several personas and aliases tracked by different vendors: Agonizing Serpens (Unit 42), Pink Sandstorm and AMERICIUM (Microsoft), and BlackShadow — a public-facing persona used to claim attacks and leak stolen data. The sub-group N3TWoRM has been linked to coordinated ransomware campaigns overlapping with Agrius activity in 2021. Microsoft previously tracked an early staging identity as DEV-0227 before formal naming.

Most Common Tactics

Targeted Regions

Europe
EU
Europe
Europe
May 2021 ~ May 2021
Hong Kong
HK
Hong Kong
Hong Kong
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Iran
IR
Iran
Iran
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Israel
IL
Israel
Israel
Nov 2020 ~ May 2021
Dec 2020 ~ Sep 2021
May 2021 ~ Jul 2021
Apr 2021 ~ May 2021
May 2021 ~ May 2021
Nov 2020 ~ May 2021
Dec 2020 ~ Sep 2021
May 2021 ~ Jul 2021
Dec 2020 ~ Sep 2021
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Jan 2023 ~ Nov 2023
May 2023 ~ May 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Jan 2023 ~ Nov 2023
Middle East
ME
Middle East
Middle East
Nov 2020 ~ May 2021
May 2021 ~ May 2021
Nov 2020 ~ May 2021
Pakistan
PK
Pakistan
Pakistan
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Saudi Arabia
SA
Saudi Arabia
Saudi Arabia
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
South Africa
ZA
South Africa
South Africa
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Turkey
TR
Turkey
Turkey
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
United Arab Emirates
AE
United Arab Emirates
United Arab Emirates
Nov 2020 ~ May 2021
Nov 2020 ~ May 2021
Jan 2020Sep 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.