LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1030: Agrius

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.[1][2] Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).[3]

EnterpriseG1030GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Agrius matters because ATT&CK links the group to ransomware and wiper operations, where the business issue is not only data theft but operational disruption and recovery readiness. The supplied relationships show a pattern that defenders should treat as credential-driven intrusion activity followed by discovery, lateral movement, collection, possible exfiltration, and destructive or extortion malware on Windows-related tooling.

Executive priority

Prioritize Agrius as a resilience and incident-readiness planning scenario, especially for organizations with Middle East or Israeli exposure noted in public reporting. Leaders should ask whether identity controls, backup recovery, endpoint visibility, and destructive-malware response playbooks are tested together, not separately. The decision value is determining whether the organization can detect credential theft and lateral movement early enough to prevent ransomware or wiper-stage impact, and whether audit evidence exists for privileged access control, logging, and recovery testing.

Technical view

ATT&CK provides no group-level detection text or group platforms, so validation should be relationship-driven. The related software and techniques point to Windows-heavy activity including Mimikatz, ASPXSpy, IPsec Helper, Apostle, DEADWOOD, MultiLayer Wiper, BFG Agonizer, and Moneybird, plus credential access against LSASS and SAM, password spraying/brute force, domain account abuse, RDP lateral movement, command shell execution, discovery, local staging, exfiltration over C2, masquerading, and deobfuscation. SOC and IR teams should validate visibility across credential access, remote logons, web shell indicators, internal scanning, suspicious command execution, data staging, and destructive file activity.

Likely telemetry

  • Windows endpoint process creation and command-line logs, especially cmd.exe, credential-dumping tools, suspicious .NET/C++ executables, and renamed or masqueraded binaries
  • Windows security events for privileged logons, domain account use, failed authentication patterns, password spraying, RDP sessions, and lateral movement
  • EDR memory-access telemetry for LSASS and registry/SAM access where available
  • Web server logs and file integrity evidence relevant to ASPX web shells
  • Network telemetry for internal host and service discovery, unusual SMB/RDP activity, and possible C2/exfiltration channels

Detection direction

  • Map detections to the related techniques rather than relying on a single Agrius indicator set, because the supplied ATT&CK object has no official detection section.
  • Correlate credential-access signals with later RDP, domain account use, discovery, and data staging; isolated alerts may look administrative, but the sequence is higher risk.
  • Tune password spraying and brute-force analytics to account for low-and-slow attempts across many accounts and identity providers where telemetry exists.
  • Hunt for web shell behavior on Windows web servers, including unusual ASPX files, abnormal child processes, and unexpected outbound connections.
  • Validate destructive-malware detections through behavior such as mass file overwrite/deletion, anomalous compilation or metadata where observable, and ransom-note creation, while avoiding assumptions that every ransomware alert is Agrius-related.

Mitigation priorities

  • Start with identity hardening: enforce strong authentication, reduce standing domain privileges, monitor privileged accounts, and address password spraying exposure.
  • Protect credential material on Windows systems by limiting administrative access, hardening LSASS-related protections where applicable, and monitoring SAM/credential access attempts.
  • Restrict and monitor RDP and other remote administration paths, especially between user workstations and servers.
  • Harden internet-facing web applications and servers against web shell persistence, and maintain file integrity and web log review procedures.
  • Segment networks and limit lateral movement paths so discovery and remote access do not easily reach critical systems.
Additional notes and limits

Aliases supplied for this group include Agrius, Pink Sandstorm, AMERICIUM, Agonizing Serpens, and BlackShadow. Public reporting cited by ATT&CK links the group to Iran’s Ministry of Intelligence and Security and describes ransomware and wiper operations with emphasis on Israeli targets. The relationship set is especially useful for defenders because it connects the group to credential dumping, password attacks, domain account abuse, RDP, collection, exfiltration, and multiple wiper/ransomware malware families.

ATT&CK does not provide group-level platforms, tactics, labels, or official detection guidance for this object. Platform and tactic references in this take are derived only from the supplied related software and technique records, many of which are broader ATT&CK technique descriptions rather than Agrius-specific observations. Local exposure, telemetry quality, and control effectiveness must be validated in the organization’s own environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Agrius

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.[1][2] Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).[3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

22 rows
DomainIDNameRelationship / procedure
EnterpriseT1018Remote System Discovery

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.[4]

EnterpriseT1685Disable or Modify Tools

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.[4]

EnterpriseT1046Network Service Discovery

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.[4]

EnterpriseT1078.002Domain AccountsSub-technique

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.[4]

EnterpriseT1140Deobfuscate/Decode Files or Information

Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.[1]

EnterpriseT1505.003Web ShellSub-technique

Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.[1]

EnterpriseT1005Data from Local System

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.[4]

EnterpriseT1583Acquire Infrastructure

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.[1]

EnterpriseT1074.001Local Data StagingSub-technique

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.[4]

EnterpriseT1110.003Password SprayingSub-technique

Agrius engaged in password spraying via SMB in victim environments.[4]

EnterpriseT1119Automated Collection

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.[4]

EnterpriseT1003.002Security Account ManagerSub-technique

Agrius dumped the SAM file on victim machines to capture credentials.[4]

EnterpriseT1560.001Archive via UtilitySub-technique

Agrius used 7zip to archive extracted data in preparation for exfiltration.[4]

EnterpriseT1036Masquerading

Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.[4]

EnterpriseT1003.001LSASS MemorySub-technique

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.[4]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts.[1] Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.[4]

EnterpriseT1190Exploit Public-Facing Application

Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity.[1]

EnterpriseT1110Brute Force

Agrius engaged in various brute forcing activities via SMB in victim environments.[4]

EnterpriseT1059.003Windows Command ShellSub-technique

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.[1]

EnterpriseT1543.003Windows ServiceSub-technique

Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.[1]

EnterpriseT1041Exfiltration Over C2 Channel

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.[4]

EnterpriseT1570Lateral Tool Transfer

Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
MalwareEnterprise

S1132: IPsec Helper

IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.[1]

Windows
MalwareEnterprise

S1137: Moneybird

Moneybird is a ransomware variant written in C++ associated with Agrius operations. The name "Moneybird" is contained in the malware's ransom note and as strings in the executable.[1]

Windows
MalwareEnterprise

S1134: DEADWOOD

DEADWOOD is wiper malware written in C++ using Boost libraries. DEADWOOD was first observed in an unattributed wiping event in Saudi Arabia in 2019, and has since been incorporated into Agrius operations.[1]

Windows
MalwareEnterprise

S1133: Apostle

Apostle is malware that has functioned as both a wiper and, in more recent versions, as ransomware. Apostle is written in .NET and shares various programming and functional overlaps with IPsec Helper.[1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
c9d623aad68f51ce...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlec9d623aad68f…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  2. [2]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  3. [3]
    Microsoft Iran Cyber 2023

    Microsoft Threat Intelligence. (2023, May 2). Iran turning to cyber-enabled influence operations for greater effect. Retrieved May 21, 2024.

    Open source URL
  4. [4]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  5. [5]
    AMERICIUM

    (Citation: Microsoft Threat Actor Naming July 2023)

  6. [6]
    AMERICIUM

    (Citation: Microsoft Threat Actor Naming July 2023)

  7. [7]
    AMERICIUM

    (Citation: Microsoft Threat Actor Naming July 2023)

  8. [8]
    Agonizing Serpens

    (Citation: Unit42 Agrius 2023)

  9. [9]
    Agonizing Serpens

    (Citation: Unit42 Agrius 2023)

  10. [10]
    Agonizing Serpens

    (Citation: Unit42 Agrius 2023)

  11. [11]
    BlackShadow

    (Citation: CheckPoint Agrius 2023)

  12. [12]
    BlackShadow

    (Citation: CheckPoint Agrius 2023)

  13. [13]
    BlackShadow

    (Citation: CheckPoint Agrius 2023)

  14. [14]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  15. [15]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  16. [16]
    Microsoft Iran Cyber 2023

    Microsoft Threat Intelligence. (2023, May 2). Iran turning to cyber-enabled influence operations for greater effect. Retrieved May 21, 2024.

    Open source URL
  17. [17]
    Microsoft Iran Cyber 2023

    Microsoft Threat Intelligence. (2023, May 2). Iran turning to cyber-enabled influence operations for greater effect. Retrieved May 21, 2024.

    Open source URL
  18. [18]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  19. [19]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  20. [20]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  21. [21]
    Pink Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  22. [22]
    Pink Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  23. [23]
    Pink Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  24. [24]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  25. [25]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  26. [26]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  27. [27]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  28. [28]
    mitre-attackG1030
    Open source URL
  29. [29]
    mitre-attackG1030
    Open source URL
  30. [30]
    mitre-attackG1030
    Open source URL
  31. [31]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  32. [32]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  33. [33]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  34. [34]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  35. [35]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  36. [36]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  37. [37]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  38. [38]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  39. [39]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  40. [40]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  41. [41]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  42. [42]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  43. [43]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  44. [44]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  45. [45]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  46. [46]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  47. [47]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  48. [48]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  49. [49]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  50. [50]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  51. [51]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  52. [52]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  53. [53]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  54. [54]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  55. [55]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  56. [56]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  57. [57]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  58. [58]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  59. [59]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  60. [60]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  61. [61]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  62. [62]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  63. [63]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  64. [64]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  65. [65]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  66. [66]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  67. [67]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  68. [68]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  69. [69]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  70. [70]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  71. [71]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  72. [72]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  73. [73]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  74. [74]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  75. [75]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  76. [76]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  77. [77]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  78. [78]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  79. [79]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  80. [80]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  81. [81]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  82. [82]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  83. [83]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  84. [84]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  85. [85]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  86. [86]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  87. [87]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  88. [88]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  89. [89]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  90. [90]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  91. [91]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  92. [92]
    CheckPoint Agrius 2023

    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

    Open source URL
  93. [93]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  94. [94]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.