Agrius is an Iranian MOIS-linked destructive actor active since 2020, notorious for ransomware-disguised wiper operations against Israeli organizations, blending data theft with endpoint destruction under a false financially motivated veneer.
Agrius emerged in 2020 and was detailed by SentinelOne and Check Point, with public reporting linking it to Iran's MOIS. The group is defined by destructive intent masked as financially motivated crime: it frequently deploys ransomware or ransom notes as cover for wipers, aiming to destroy data and disrupt operations rather than genuinely extort.
Its toolset has evolved through named wipers and ransomware including Apostle, Fantasy, Moneybird, MultiLayer, PartialWasher, and BFG Agonizer, often paired with data-theft utilities such as a bespoke Sqlextractor for pillaging database servers before destruction. Under the BlackShadow persona it has also conducted hack-and-leak operations for psychological effect.
MENA targeting is overwhelmingly Israel-focused, with additional activity touching the UAE. Unit 42, tracking the group as Agonizing Serpens, documented a January–October 2023 wave against Israeli higher-education and technology organizations that stole PII and intellectual property before deploying multiple wipers to render endpoints unusable; Check Point separately reported Moneybird ransomware against Israeli targets in 2023.
Agrius remains an active destructive threat aligned to Iranian retaliatory objectives against Israel. Its consistent fusion of espionage-style data theft with wiper deployment and occasional leak operations places it alongside Void Manticore and WIRTE in the cohort of Iran-aligned actors conducting disruptive attacks amid ongoing regional conflict.