Agrius: From Espionage to Destructive Cyber Attacks in the Middle East
- Actor Motivations: Espionage,Extortion,Sabotage
- Attack Vectors: Compromised Credentials,SQL injection,Vulnerability Exploitation,Backdoor,Ransomware,Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Agrius threat actor evolved from conducting espionage to destructive attacks, notably using wipers disguised as ransomware. Initially engaging in data destruction under the guise of encryption for ransom, Agrius later developed fully functional ransomware, targeting primarily Israel and the UAE's critical facilities. Utilizing VPNs for anonymity, Agrius exploited public-facing applications, deploying webshells for initial access, and custom .NET malware, 'IPsec Helper', for persistence and data exfiltration. Their toolkit includes the .NET-based 'Apostle' wiper-turned-ransomware and the DEADWOOD wiper, indicating a sophisticated approach to cyber sabotage and espionage.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | High |
| Region | Iran | Medium |
| Region | Israel | Verified |
| Region | Pakistan | Medium |
| Region | Saudi Arabia | Medium |
| Region | Turkey | Medium |
| Region | United Arab Emirates | Verified |
| Region | Middle East Countries | Verified |
Exploited Vulnerabilities
Extracted IOCs
- theisnonamelikethis29123[.]com
- whynooneistherefornoneofthem[.]com
- 01ed1914b55a2d6ca4e4c97827fba3f4
- 02aa4ba656d49ebbe930b923b8399b6b
- 1caaacebe309474d36d8243a3c393351
- 32616cdd343ad938e385b32aa482fea4
- 338236f51e666e26e4547273e9a23d98
- 4ea373d0ab8d50b644c95f415e1c0694
- 851b7b8dd006dc889bf8f9282dc853ce
- 857ef30bf15ea3da9b94092da78ef0fc
- 9d7d20a21cf00f43e1b1701df368e172
- a60c177bb5d293d0a0d7231f0b8cad6b
- a9ee524171107deb0732102dee81e7bb
- aad3908e52c6987a626e4350f8f50f62
- aea6ab1ffa2243b94ebcca7759e60f64
- b05a582e28e349cbb252a7c3f5060862
- b451592c0934e8d91197dab1d846d9c8
- c125149b44be78fae9ba3eb1f33d03dc
- d1645e55e4d10d9992793d66206fce94
- d40453a154d9254919ebf575eecdc590
- e575a627a5a98833f9fd48458e342276
- ef0740198be26c0ba32c0332a2afe133
- f88d308b1b4e6e41a9a17455978ec24b
- 067bdb137d527f6986629dd63357592e8ad7ea92
- 069e082caf0dafd3fef51b4b0be0e4e21919ae27
- 195188bfc99bbdc2d29952ed10a8413b362f4373
- 2e488d98a99a0fdffd1e8ae85b3485366ae8287b
- 3259b88515f97d999256fcd3bb7a75a0d4173e9c
- 34c1117f7a38eb78743f6a9f433f03e195e1b4e0
- 4e74671a06748794d28c64781c3d2c96664f82a9
- 4e83e61efe0af873c282336a140e899340647551
- 58cb07bf3af30363e52d64af61fe832ecc9ba70d
- 58d58356b7a1aa69e60b72be4dc2e2499929274a
- 5ab8582a892c603b00c0989eedca668e55abbba5
- 65ee66050faf0fe9c023cfc15edb73cf7f77fe4d
- 7ce212c0a1721071351c0176fa691d6665a7bcb5
- 84aad01489fe6eefd79ef1cbb771eb76fce58fe3
- 9c9a5184ba377bce87fb3b4483331866f392afde
- a64924df986c1682fd4f37153a917ee454a18315
- be2dd26946bc0ca3ec8683568dc73a5852d79235
- c53e3ff5c3c522738ac1dfbd4e70f88a14b0f599
- d2fff8dec081efd972739acf2a877557397bcbb9
- e805de2d8925af37cfd4f26f7ac3e38cd7fedd36
- f5221ddbae00e6cf2c37d5c4bdb22567fa7bbae1
- f5acabb74864e95b69597b0785ef944f445c9683
- 18c92f23b646eb85d67a890296000212091f930b1fe9e92033f123be3581a90f
- 19dbed996b1a814658bef433bad62b03e5c59c2bf2351b793d1a5d4a5216d27e
- 3e9c6f384b63ebeaa729b7c97a179d409cdd859315ee2f6372a2a550e567445f
- 40f329d0aaba0d55fc657802761c78be74e19a553de6fd2df592bccf3119ec16
- 4a50073f841a1beaa5900241fce76ed242659130e065dbd38be318a650b1264a
- 5eb5922b467474dccc7ab8780e32697f5afd59e8108b0cdafefb627b02bbd9ba
- 5f5edae2cae4db0ee988962ca2e7cccd1892e4f4b512fbb780210595c7ba7088
- 6505ecd35e45e521f5e37febd01be04166d725ba87552777c17517533afc6329
- 6fb07a9855edc862e59145aed973de9d459a6f45f17a8e779b95d4c55502dcce
- 7b525fe7117ffd8df01588efb874c1b87e4ad2cd7d1e1ceecb5baf2e9c052a52
- 85f16df007fc848731ed02e0c3d8dd3ab1f2f2bf8c1b6999f7d9ff98a1cac1c7
- 96cc69242a7900810c4d2e9f3f55aad8edb89137959f4c370f80a6e574ddc201
- b30405d654c1bfcd5e2bd338cc16e971738ceb6ba069da413195358b9ca3a2a2
- b5149c1aae5c899a0f3a4be162e24c08d284f67f6b9fb70439ce6d91353a540c
- bac77143cb8829c802a6723a397277aa34ba2738103d78517b36c6cfb06724ef
- ccfc0a2652916543e0ce972b38ba50815e8df11387502519607c9fd4f91d635f
- df94d32997e22bae2e5745eb3120947b025f79a16cf4b710131f911b12d960cc
- e37bfad12d44a247ac99fdf30f5ac40a0448a097e36f3dbba532688b5678ad13
- e4ea1728e19699612b5614cc0b8829a4bf749870648be6efc1b8a88c036f3607
- e889d4b2cfb48b6e8f972846538dfbc057dbfc35fa28f0515cad4d60780a9872
- f18dd50dde8c1101eb3c892fc2bf04b7779c2c0def27de1d6c1fd341f3ecdf6c
- fc949bd5aa0e704901f12624badd591768ea5613560bd3d88c396479235da095
- 185[.]142.97.81
- 185[.]142.98.32
- 185[.]147.131.81
- 195[.]123.208.152
- 37[.]120.238.15
- 37[.]59.236.232
- 5[.]2.67.85
- 5[.]2.73.67
- 54[.]37.99.4
- 81[.]177.22.16
- 81[.]177.23.16
- 95[.]211.140.221
- hxxp://185[.]142.97.81/css/v1/template/main[.]php
- hxxp://185[.]142.98.32/scripts/_data/25/lastupdate[.]php
- hxxp://195[.]123.208.152/admins/login[.]php
- hxxp://5[.]2.67.85/view/list[.]php
- hxxp://5[.]2.73.67/panel/new/file/css/boot[.]php
- hxxp://theisnonamelikethis29123[.]com/mail.php
- hxxp://whynooneistherefornoneofthem[.]com/about.php
Tip: 86 related IOCs (12 IP, 2 domain, 7 URL, 0 email, 65 file hash) to this threat have been found.
Overlaps
Source: Cybereason - October 2021
Detection (one case): whynooneistherefornoneofthem[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Agrius Threat Campaign
A newly identified threat group launched severe cyberattacks against organizations, disguising their actions as standard ransomware incidents. In reality, the attackers permanently destroyed the victims' data, meaning it could not be recovered even if a ransom was paid.
The attacks were carried out by a new group known as "Agrius". Based on technical analysis of their tools, infrastructure, and historical alignment with regional disputes, researchers believe with medium confidence that this group is affiliated with Iran.
The primary goal of Agrius was disruption and data destruction rather than financial gain. By masking their wiping software as ransomware, the operators attempted to cause maximum impact while maintaining deniability for the state sponsor.
The group primarily focused on the Middle East. They opportunistically attacked organizations in Israel and specifically targeted a critical, nation-owned facility in the United Arab Emirates.
The attackers began by finding and exploiting security weaknesses in public-facing internet applications to get inside the target networks. Once inside, they used specialized tools to steal passwords, move quietly through the network, and install their destructive data-wiping software.
Targets like Israeli organizations and critical infrastructure in the United Arab Emirates are likely chosen due to ongoing regional disputes. Attacking these entities allows state-sponsored groups to cause significant societal impact and send a geopolitical message.
Organizations should ensure that all internet-facing applications are promptly updated to fix known security vulnerabilities. Additionally, monitoring for unusual remote connections and hunting for unauthorized administrative tools can help detect an intrusion before data destruction occurs.
While the group searches for vulnerable systems opportunistically, the ultimate execution of their destructive payload appears targeted. The attacks are heavily concentrated on specific regions, namely organizations within the Middle East.