← Back to Actors
Agrius
AgriusPink SandstormAMERICIUMAgonizing SerpensBlackShadow
[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked [Agrius](https://attack.mitre.org/groups/G1030) to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)
23
Techniques
23
Covered
0
Gaps
100%
Coverage
Coverage23/23
COVERED (23)
T1003.001LSASS Memory111 det.T1003.002Security Account Manager49 det.T1005Data from Local System47 det.T1018Remote System Discovery50 det.T1021.001Remote Desktop Protocol53 det.T1036Masquerading525 det.T1041Exfiltration Over C2 Channel31 det.T1046Network Service Discovery51 det.T1059.003Windows Command Shell82 det.T1074.001Local Data Staging10 det.T1078.002Domain Accounts28 det.T1110Brute Force90 det.T1110.003Password Spraying66 det.T1119Automated Collection12 det.T1140Deobfuscate/Decode Files or Information58 det.T1190Exploit Public-Facing Application216 det.T1505.003Web Shell63 det.T1543.003Windows Service79 det.T1560.001Archive via Utility26 det.T1562.001Disable or Modify Tools311 det.T1570Lateral Tool Transfer22 det.T1583Acquire Infrastructure1 det.T1685Disable or Modify Tools278 det.