Threats Feed|Agrius|Last Updated 08/06/2026|AuthorCertfa Radar|Publish Date25/05/2021

Agrius: From Espionage to Destructive Cyber Attacks in the Middle East

  • Actor Motivations: Espionage,Extortion,Sabotage
  • Attack Vectors: Compromised Credentials,SQL injection,Vulnerability Exploitation,Backdoor,Ransomware,Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Agrius threat actor evolved from conducting espionage to destructive attacks, notably using wipers disguised as ransomware. Initially engaging in data destruction under the guise of encryption for ransom, Agrius later developed fully functional ransomware, targeting primarily Israel and the UAE's critical facilities. Utilizing VPNs for anonymity, Agrius exploited public-facing applications, deploying webshells for initial access, and custom .NET malware, 'IPsec Helper', for persistence and data exfiltration. Their toolkit includes the .NET-based 'Apostle' wiper-turned-ransomware and the DEADWOOD wiper, indicating a sophisticated approach to cyber sabotage and espionage.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
High
RegionIran
Medium
RegionIsrael
Verified
RegionPakistan
Medium
RegionSaudi Arabia
Medium
RegionTurkey
Medium
RegionUnited Arab Emirates
Verified
RegionMiddle East Countries
Verified

Exploited Vulnerabilities

Extracted IOCs

  • theisnonamelikethis29123[.]com
  • whynooneistherefornoneofthem[.]com
  • 01ed1914b55a2d6ca4e4c97827fba3f4
  • 02aa4ba656d49ebbe930b923b8399b6b
  • 1caaacebe309474d36d8243a3c393351
  • 32616cdd343ad938e385b32aa482fea4
  • 338236f51e666e26e4547273e9a23d98
  • 4ea373d0ab8d50b644c95f415e1c0694
  • 851b7b8dd006dc889bf8f9282dc853ce
  • 857ef30bf15ea3da9b94092da78ef0fc
  • 9d7d20a21cf00f43e1b1701df368e172
  • a60c177bb5d293d0a0d7231f0b8cad6b
  • a9ee524171107deb0732102dee81e7bb
  • aad3908e52c6987a626e4350f8f50f62
  • aea6ab1ffa2243b94ebcca7759e60f64
  • b05a582e28e349cbb252a7c3f5060862
  • b451592c0934e8d91197dab1d846d9c8
  • c125149b44be78fae9ba3eb1f33d03dc
  • d1645e55e4d10d9992793d66206fce94
  • d40453a154d9254919ebf575eecdc590
  • e575a627a5a98833f9fd48458e342276
  • ef0740198be26c0ba32c0332a2afe133
  • f88d308b1b4e6e41a9a17455978ec24b
  • 067bdb137d527f6986629dd63357592e8ad7ea92
  • 069e082caf0dafd3fef51b4b0be0e4e21919ae27
  • 195188bfc99bbdc2d29952ed10a8413b362f4373
  • 2e488d98a99a0fdffd1e8ae85b3485366ae8287b
  • 3259b88515f97d999256fcd3bb7a75a0d4173e9c
  • 34c1117f7a38eb78743f6a9f433f03e195e1b4e0
  • 4e74671a06748794d28c64781c3d2c96664f82a9
  • 4e83e61efe0af873c282336a140e899340647551
  • 58cb07bf3af30363e52d64af61fe832ecc9ba70d
  • 58d58356b7a1aa69e60b72be4dc2e2499929274a
  • 5ab8582a892c603b00c0989eedca668e55abbba5
  • 65ee66050faf0fe9c023cfc15edb73cf7f77fe4d
  • 7ce212c0a1721071351c0176fa691d6665a7bcb5
  • 84aad01489fe6eefd79ef1cbb771eb76fce58fe3
  • 9c9a5184ba377bce87fb3b4483331866f392afde
  • a64924df986c1682fd4f37153a917ee454a18315
  • be2dd26946bc0ca3ec8683568dc73a5852d79235
  • c53e3ff5c3c522738ac1dfbd4e70f88a14b0f599
  • d2fff8dec081efd972739acf2a877557397bcbb9
  • e805de2d8925af37cfd4f26f7ac3e38cd7fedd36
  • f5221ddbae00e6cf2c37d5c4bdb22567fa7bbae1
  • f5acabb74864e95b69597b0785ef944f445c9683
  • 18c92f23b646eb85d67a890296000212091f930b1fe9e92033f123be3581a90f
  • 19dbed996b1a814658bef433bad62b03e5c59c2bf2351b793d1a5d4a5216d27e
  • 3e9c6f384b63ebeaa729b7c97a179d409cdd859315ee2f6372a2a550e567445f
  • 40f329d0aaba0d55fc657802761c78be74e19a553de6fd2df592bccf3119ec16
  • 4a50073f841a1beaa5900241fce76ed242659130e065dbd38be318a650b1264a
  • 5eb5922b467474dccc7ab8780e32697f5afd59e8108b0cdafefb627b02bbd9ba
  • 5f5edae2cae4db0ee988962ca2e7cccd1892e4f4b512fbb780210595c7ba7088
  • 6505ecd35e45e521f5e37febd01be04166d725ba87552777c17517533afc6329
  • 6fb07a9855edc862e59145aed973de9d459a6f45f17a8e779b95d4c55502dcce
  • 7b525fe7117ffd8df01588efb874c1b87e4ad2cd7d1e1ceecb5baf2e9c052a52
  • 85f16df007fc848731ed02e0c3d8dd3ab1f2f2bf8c1b6999f7d9ff98a1cac1c7
  • 96cc69242a7900810c4d2e9f3f55aad8edb89137959f4c370f80a6e574ddc201
  • b30405d654c1bfcd5e2bd338cc16e971738ceb6ba069da413195358b9ca3a2a2
  • b5149c1aae5c899a0f3a4be162e24c08d284f67f6b9fb70439ce6d91353a540c
  • bac77143cb8829c802a6723a397277aa34ba2738103d78517b36c6cfb06724ef
  • ccfc0a2652916543e0ce972b38ba50815e8df11387502519607c9fd4f91d635f
  • df94d32997e22bae2e5745eb3120947b025f79a16cf4b710131f911b12d960cc
  • e37bfad12d44a247ac99fdf30f5ac40a0448a097e36f3dbba532688b5678ad13
  • e4ea1728e19699612b5614cc0b8829a4bf749870648be6efc1b8a88c036f3607
  • e889d4b2cfb48b6e8f972846538dfbc057dbfc35fa28f0515cad4d60780a9872
  • f18dd50dde8c1101eb3c892fc2bf04b7779c2c0def27de1d6c1fd341f3ecdf6c
  • fc949bd5aa0e704901f12624badd591768ea5613560bd3d88c396479235da095
  • 185[.]142.97.81
  • 185[.]142.98.32
  • 185[.]147.131.81
  • 195[.]123.208.152
  • 37[.]120.238.15
  • 37[.]59.236.232
  • 5[.]2.67.85
  • 5[.]2.73.67
  • 54[.]37.99.4
  • 81[.]177.22.16
  • 81[.]177.23.16
  • 95[.]211.140.221
  • hxxp://185[.]142.97.81/css/v1/template/main[.]php
  • hxxp://185[.]142.98.32/scripts/_data/25/lastupdate[.]php
  • hxxp://195[.]123.208.152/admins/login[.]php
  • hxxp://5[.]2.67.85/view/list[.]php
  • hxxp://5[.]2.73.67/panel/new/file/css/boot[.]php
  • hxxp://theisnonamelikethis29123[.]com/mail.php
  • hxxp://whynooneistherefornoneofthem[.]com/about.php
download

Tip: 86 related IOCs (12 IP, 2 domain, 7 URL, 0 email, 65 file hash) to this threat have been found.

Overlaps

MalKamakMalKamak's GhostShell Campaign Hits Middle East, U.S., and Europe

Source: Cybereason - October 2021

Detection (one case): whynooneistherefornoneofthem[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Agrius Threat Campaign

A newly identified threat group launched severe cyberattacks against organizations, disguising their actions as standard ransomware incidents. In reality, the attackers permanently destroyed the victims' data, meaning it could not be recovered even if a ransom was paid.

The attacks were carried out by a new group known as "Agrius". Based on technical analysis of their tools, infrastructure, and historical alignment with regional disputes, researchers believe with medium confidence that this group is affiliated with Iran.

The primary goal of Agrius was disruption and data destruction rather than financial gain. By masking their wiping software as ransomware, the operators attempted to cause maximum impact while maintaining deniability for the state sponsor.

The group primarily focused on the Middle East. They opportunistically attacked organizations in Israel and specifically targeted a critical, nation-owned facility in the United Arab Emirates.

The attackers began by finding and exploiting security weaknesses in public-facing internet applications to get inside the target networks. Once inside, they used specialized tools to steal passwords, move quietly through the network, and install their destructive data-wiping software.

Targets like Israeli organizations and critical infrastructure in the United Arab Emirates are likely chosen due to ongoing regional disputes. Attacking these entities allows state-sponsored groups to cause significant societal impact and send a geopolitical message.

Organizations should ensure that all internet-facing applications are promptly updated to fix known security vulnerabilities. Additionally, monitoring for unusual remote connections and hunting for unauthorized administrative tools can help detect an intrusion before data destruction occurs.

While the group searches for vulnerable systems opportunistically, the ultimate execution of their destructive payload appears targeted. The attacks are heavily concentrated on specific regions, namely organizations within the Middle East.

About Affiliation
Agrius
Agrius is an Iranian state-linked threat actor active since at least 2020, assessed by multiple vendors to operate on behalf of Iran's Ministry of Intelligence and Security (MOIS). The group is best known for destructive wiper and fake-ransomware campaigns aimed primarily at Israeli organizations across the technology, education, insurance, and healthcare sectors. Agrius gains initial access by exploiting public-facing web applications, deploys ASPXSpy-based web shells for persistence, and ultimately delivers custom wipers such as Apostle and DEADWOOD to destroy data and disrupt operations. Microsoft tracks the same cluster as Pink Sandstorm and AMERICIUM.
View Agrius's Insights