Threat actor · all actors
AgriusG1030 state
🇮🇷 IR
aka Agrius, Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow, DEV-0022, UNC2428, Black Shadow, SPECTRAL KITTEN
Last updated: 2026-08-20
About this actor
Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, primarily targeting Israeli organizations in the education and technology sectors. The group has strong connections to Iran's Ministry of Intelligence and Security and has been observed using various tools and techniques to bypass security measures. They aim to steal sensitive information, including PII and intellectual property, and inflict damage by wiping endpoints.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 30 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1005Data from Local System ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1036Masquerading ↗T1041Exfiltration Over C2 Channel ↗T1046Network Service Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1110Brute Force ↗T1110.003Password Spraying ↗T1119Automated Collection ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1570Lateral Tool Transfer ↗T1583Acquire Infrastructure ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 24 / 30 | 80% |
AC-3 | 21 / 30 | 70% |
AC-2 | 20 / 30 | 67% |
AC-6 | 20 / 30 | 67% |
CM-2 | 20 / 30 | 67% |
CM-6 | 20 / 30 | 67% |
AC-5 | 16 / 30 | 53% |
IA-2 | 15 / 30 | 50% |
SI-3 | 15 / 30 | 50% |
CA-7 | 14 / 30 | 47% |
CM-5 | 13 / 30 | 43% |
CM-7 | 13 / 30 | 43% |
RA-5 | 11 / 30 | 37% |
IA-5 | 9 / 30 | 30% |
SI-7 | 9 / 30 | 30% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- APT5 0.36
- GALLIUM 0.34
- HomeLand Justice 0.29
- 2016 Ukraine Electric Power Attack 0.29
- APT28 Nearest Neighbor Campaign 0.29
Same nation-state
- HomeLand Justice 1.00
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- OilRig 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00