🌐Agrius
🌐 Agrius is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 22 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
22Techniques
0IOCs
About this actor (MITRE)
[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked [Agrius](https://attack.mitre.org/groups/G1030) to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)
Known aliases
AgriusPink SandstormAMERICIUMAgonizing SerpensBlackShadow
Top techniques
All other tracked techniques
T1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1036 · MasqueradingT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1059.003 · Windows Command ShellT1074.001 · Local Data StagingT1078.002 · Domain AccountsT1110 · Brute ForceT1110.003 · Password SprayingT1119 · Automated CollectionT1140 · Deobfuscate/Decode Files or InformationT1190 · Exploit Public-Facing ApplicationT1505.003 · Web ShellT1543.003 · Windows ServiceT1560.001 · Archive via UtilityT1570 · Lateral Tool TransferT1583 · Acquire InfrastructureT1685 · Disable or Modify Tools