◇ SIGN IN
← all actors
apt

Agrius (Agonizing Serpens / BlackShadow)

activehigh confidence
APT / State-sponsored
Agonizing SerpensBlackShadowPink SandstormAMERICIUM
Attribution
Iran — Ministry of Intelligence and Security (MOIS)
Origin
Iran
First seen
2020
Last active
2025
Motivation
Sabotage
Confidence
high
MENA targeting
Israel, UAE
Sectors
Education, technology, diamond industry
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Israel, UAE (Education, technology, diamond industry sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Agrius is an Iranian MOIS-linked destructive actor active since 2020, notorious for ransomware-disguised wiper operations against Israeli organizations, blending data theft with endpoint destruction under a false financially motivated veneer.

History

Agrius emerged in 2020 and was detailed by SentinelOne and Check Point, with public reporting linking it to Iran's MOIS. The group is defined by destructive intent masked as financially motivated crime: it frequently deploys ransomware or ransom notes as cover for wipers, aiming to destroy data and disrupt operations rather than genuinely extort.

Its toolset has evolved through named wipers and ransomware including Apostle, Fantasy, Moneybird, MultiLayer, PartialWasher, and BFG Agonizer, often paired with data-theft utilities such as a bespoke Sqlextractor for pillaging database servers before destruction. Under the BlackShadow persona it has also conducted hack-and-leak operations for psychological effect.

MENA targeting is overwhelmingly Israel-focused, with additional activity touching the UAE. Unit 42, tracking the group as Agonizing Serpens, documented a January–October 2023 wave against Israeli higher-education and technology organizations that stole PII and intellectual property before deploying multiple wipers to render endpoints unusable; Check Point separately reported Moneybird ransomware against Israeli targets in 2023.

Agrius remains an active destructive threat aligned to Iranian retaliatory objectives against Israel. Its consistent fusion of espionage-style data theft with wiper deployment and occasional leak operations places it alongside Void Manticore and WIRTE in the cohort of Iran-aligned actors conducting disruptive attacks amid ongoing regional conflict.

Notable campaigns

2021
Apostle wiper / DEADWOOD
Early wiper operations disguised as ransomware against Israeli targets.
2023
Moneybird ransomware
Check Point-documented ransomware-as-cover attacks against Israeli organizations.
2023
Agonizing Serpens (education/tech)
Data theft followed by MultiLayer, PartialWasher, and BFG Agonizer wipers against Israeli universities and tech firms.