SYMBOL | COMMON_NAME | aka. SYNONYMS |
Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, primarily targeting Israeli organizations in the education and technology sectors. The group has strong connections to Iran's Ministry of Intelligence and Security and has been observed using various tools and techniques to bypass security measures. They aim to steal sensitive information, including PII and intellectual property, and inflict damage by wiping endpoints.
2024-01-02
⋅
OODA Loop
⋅
Critical Infrastructure Remains the Brass Ring for Cyber Attackers in 2024 Pink Sandstorm |
2023-11-09
⋅
SOC Prime
⋅
Agonizing Serpens Attack Detection: Iran-Backed Hackers Target Israeli Tech Firms and Educational Institutions Pink Sandstorm |
2023-11-06
⋅
Palo Alto Networks Unit 42
⋅
Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors Apostle Pink Sandstorm |
2023-11-06
⋅
The Record
⋅
Iran-linked hackers attack Israeli education and tech organizations Pink Sandstorm |
2023-05-26
⋅
enigmasoft
⋅
Moneybird Ransomware Pink Sandstorm |
2023-05-24
⋅
Check Point Research
⋅
Agrius Deploys MoneyBird in Targeted Attacks against Israeli Organizations Pink Sandstorm |
2022-12-07
⋅
ESET Research
⋅
Fantasy – a new Agrius wiper deployed through a supply‑chain attack Apostle DEADWOOD |
2022-08-12
⋅
CrowdStrike
⋅
The Anatomy of Wiper Malware, Part 1: Common Techniques Apostle CaddyWiper DEADWOOD DistTrack DoubleZero DUSTMAN HermeticWiper IsaacWiper IsraBye KillDisk Meteor Olympic Destroyer Ordinypt Petya Sierra(Alfa,Bravo, ...) StoneDrill WhisperGate ZeroCleare |
2021-09-30
⋅
SentinelOne
⋅
New Version Of Apostle Ransomware Reemerges In Targeted Attack On Higher Education Apostle |
2021-05-27
⋅
cyberpunkleigh
⋅
Apostle Ransomware Analysis Apostle |
2021-05-25
⋅
SentinelOne
⋅
From Wiper to Ransomware: The Evolution of Agrius Apostle DEADWOOD |