Agonizing Serpens APT Targets Israeli Education and Tech Sectors in Sophisticated Cyberattacks
- Actor Motivations: Espionage,Exfiltration,Sabotage
- Attack Vectors: Brute-force,Vulnerability Exploitation,Dropper,Malware,Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Agonizing Serpens APT group conducted a series of cyberattacks on Israel's education and technology sectors from January to October 2023. These attacks involved stealing sensitive data, including personal and intellectual property, followed by deploying various wipers like MultiLayer, PartialWasher, and BFG Agonizer to erase traces and disable endpoints. Techniques used included exploiting web servers, deploying web shells, network scanning with Nbtscan and WinEggDrop, credential theft via Mimikatz, and data exfiltration using tools like WinSCP. The group's upgraded capabilities aimed to bypass endpoint detection and response (EDR) systems, employing a mix of known and custom tools for evasion.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Information Technology | Verified |
| Sector | Education | Verified |
| Region | Israel | Verified |
Extracted IOCs
- 13d8d4f4fa483111e4372a6925d24e28f3be082a2ea8f44304384982bd692ec9
- 18c909a2b8c5e16821d6ef908f56881aa0ecceeaccb5fa1e54995935fcfd12f7
- 1ea4d26a31dad637d697f9fb70b6ed4d75a13d101e02e02bc00200b42353985c
- 2a6e3b6e42be2f55f7ab9db9d5790b0cc3f52bee9a1272fc4d79c7c0a3b6abda
- 2fb88793f8571209c2fcf1be528ca1d59e7ac62e81e73ebb5a0d77b9d5a09cb8
- 38e406b17715b1b52ed8d8e4defdb5b79a4ddea9a3381a9f2276b00449ec8835
- 49c3df62c4b62ce8960558daea4a8cf41b11c8f445e218cd257970cf939a3c25
- 5d1660a53aaf824739d82f703ed580004980d377bdc2834f1041d512e4305d07
- 62e36675ed7267536bd980c07570829fe61136e53de3336eebadeca56ab060c2
- 63d51bc3e5cf4068ff04bd3d665c101a003f1d6f52de7366f5a2d9ef5cc041a7
- 8967c83411cd96b514252df092d8d3eda3f7f2c01b3eef1394901e27465ff981
- 9165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a5
- a112e78e4f8b99b1ceddae44f34692be20ef971944b98e2def995c87d5ae89ee
- a2d8704b5073cdc059e746d2016afbaecf8546daad3dbfe4833cd3d41ab63898
- a8e63550b56178ae5198c9cc5b704a8be4c8505fea887792b6d911e488592a7c
- abfde7c29a4a703daa2b8ad2637819147de3a890fdd12da8279de51a3cc0d96d
- c52525cd7d05bddb3ee17eb1ad6b5d6670254252b28b18a1451f604dfff932a4
- dacdb4976fd75ab2fd7bb22f1b2f9d986f5d92c29555ce2b165c020e2816a200
- e43d66b7a4fa09a0714c573fbe4996770d9d85e31912480e73344124017098f9
- ec7dc5bfadce28b8a8944fb267642c6f713e5b19a9983d7c6f011ebe0f663097
- f4c8369e4de1f12cc5a71eb5586b38fc78a9d8db2b189b8c25ef17a572d4d6b7
- f65880ef9fec17da4142850e5e7d40ebfc58671f5d66395809977dd5027a6a3e
- 109[.]237.107.212
- 185[.]105.46.19
- 185[.]105.46.34
- 217[.]29.62.166
- 81[.]177.22.182
- 93[.]188.207.110
Tip: 28 related IOCs (6 IP, 0 domain, 0 URL, 0 email, 22 file hash) to this threat have been found.
Overlaps
Source: PolySwarm - September 2023
Detection (one case): f4c8369e4de1f12cc5a71eb5586b38fc78a9d8db2b189b8c25ef17a572d4d6b7
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Understanding the Agonizing Serpens Cyberattacks
Hackers breached networks to steal sensitive data and subsequently deployed destructive malware to wipe computers and servers. The attackers attempted to cover their tracks and completely destroy infected machines to disrupt normal business operations.
The attacks were carried out by an Iranian-linked threat group known as Agonizing Serpens, which is also tracked under names like Agrius, BlackShadow, and Pink Sandstorm. This group has been active since 2020 and is heavily known for conducting destructive data-wiping and fake-ransomware operations.
The campaign had two primary goals: stealing intellectual property and personal data to leak online, and intentionally destroying computer systems. The attackers sought to cause mass data loss, inflict reputational damage, and incite fear rather than demand financial ransom.
The attacks were highly focused rather than widespread globally. Threat analysts noted that their systems did not detect non-Israeli organizations being affected during this specific campaign.
Yes, the attackers specifically targeted the higher education and technology sectors within Israel. They actively sought out highly sensitive personal information, extracting ID numbers, passport scans, personal emails, and full physical addresses from databases.
The attackers first broke into the networks by finding and exploiting unprotected web servers exposed to the internet. Once inside, they mapped the network, stole administrative passwords, bundled sensitive database files into hidden archives, smuggled the data out, and finally launched custom malware to destroy the affected computers.
Education and tech institutions often hold massive amounts of sensitive personal data and valuable intellectual property. By stealing and threatening to publish this data on platforms like social media or Telegram, the attackers can maximize fear and heavily damage the reputation of those Israeli institutions.
Organizations must secure and update any servers connected directly to the internet, as this was the initial entry point. Additionally, utilizing advanced security software that monitors abnormal behavior, such as unexpected network scanning or attempts to disable security tools, can effectively stop these attacks before data is stolen or destroyed.
This is a strictly targeted issue. The attacks were part of a specific offensive campaign aimed exclusively at Israeli organizations, meaning random individuals or global businesses outside of this profile are not the primary focus of this threat.