SYMBOLCOMMON_NAMEaka. SYNONYMS

Pink Sandstorm  (Back to overview)

aka: AMERICIUM, Agonizing Serpens, Agrius, BlackShadow, DEV-0022

Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, primarily targeting Israeli organizations in the education and technology sectors. The group has strong connections to Iran's Ministry of Intelligence and Security and has been observed using various tools and techniques to bypass security measures. They aim to steal sensitive information, including PII and intellectual property, and inflict damage by wiping endpoints.


Associated Families
win.apostle

References
2024-01-02OODA LoopEmilio Iasiello
Critical Infrastructure Remains the Brass Ring for Cyber Attackers in 2024
Pink Sandstorm
2023-11-09SOC PrimeDaryna Olyniychuk
Agonizing Serpens Attack Detection: Iran-Backed Hackers Target Israeli Tech Firms and Educational Institutions
Pink Sandstorm
2023-11-06Palo Alto Networks Unit 42Assaf Dahan, Daniel Frank, Or Chechik, Tom Fakterman
Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors
Apostle Pink Sandstorm
2023-11-06The RecordDaryna Antoniuk
Iran-linked hackers attack Israeli education and tech organizations
Pink Sandstorm
2023-05-26enigmasoftMezo
Moneybird Ransomware
Pink Sandstorm
2023-05-24Check Point ResearchJiri Vinopal, Marc Salinas Fernandez
Agrius Deploys MoneyBird in Targeted Attacks against Israeli Organizations
Pink Sandstorm
2022-12-07ESET ResearchAdam Burgher
Fantasy – a new Agrius wiper deployed through a supply‑chain attack
Apostle DEADWOOD
2022-08-12CrowdStrikeIoan Iacob, Iulian Madalin Ionita
The Anatomy of Wiper Malware, Part 1: Common Techniques
Apostle CaddyWiper DEADWOOD DistTrack DoubleZero DUSTMAN HermeticWiper IsaacWiper IsraBye KillDisk Meteor Olympic Destroyer Ordinypt Petya Sierra(Alfa,Bravo, ...) StoneDrill WhisperGate ZeroCleare
2021-09-30SentinelOneAmitai Ben Shushan Ehrlich
New Version Of Apostle Ransomware Reemerges In Targeted Attack On Higher Education
Apostle
2021-05-27cyberpunkleighcyberpunkleigh
Apostle Ransomware Analysis
Apostle
2021-05-25SentinelOneAmitai Ben Shushan Ehrlich
From Wiper to Ransomware: The Evolution of Agrius
Apostle DEADWOOD

Credits: MISP Project