← Back to Actors
Agrius
AgriusPink SandstormAMERICIUMAgonizing SerpensBlackShadow
[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked [Agrius](https://attack.mitre.org/groups/G1030) to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)
22
Techniques
22
Covered
0
Gaps
100%
Coverage
Coverage22/22
COVERED (22)
T1003.001LSASS Memory105 det.T1003.002Security Account Manager45 det.T1005Data from Local System46 det.T1018Remote System Discovery46 det.T1021.001Remote Desktop Protocol51 det.T1036Masquerading493 det.T1041Exfiltration Over C2 Channel30 det.T1046Network Service Discovery49 det.T1059.003Windows Command Shell79 det.T1074.001Local Data Staging10 det.T1078.002Domain Accounts26 det.T1110Brute Force85 det.T1110.003Password Spraying65 det.T1119Automated Collection11 det.T1140Deobfuscate/Decode Files or Information55 det.T1190Exploit Public-Facing Application208 det.T1505.003Web Shell57 det.T1543.003Windows Service79 det.T1560.001Archive via Utility24 det.T1562.001Disable or Modify Tools300 det.T1570Lateral Tool Transfer20 det.T1583Acquire Infrastructure1 det.