Agrius

G1030

Threat group.View on attack.mitre.org

About this group

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).

Techniques used22

Procedure examples22

TechniqueProcedure example
T1003.001
LSASS Memory

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

T1003.002
Security Account Manager

Agrius dumped the SAM file on victim machines to capture credentials.

T1005
Data from Local System

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

T1018
Remote System Discovery

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.

T1021.001
Remote Desktop Protocol

Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.

T1036
Masquerading

Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.

T1041
Exfiltration Over C2 Channel

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

T1046
Network Service Discovery

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.

T1059.003
Windows Command Shell

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.

T1074.001
Local Data Staging

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.

T1078.002
Domain Accounts

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

T1110
Brute Force

Agrius engaged in various brute forcing activities via SMB in victim environments.

T1110.003
Password Spraying

Agrius engaged in password spraying via SMB in victim environments.

T1119
Automated Collection

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.

T1140
Deobfuscate/Decode Files or Information

Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.

View all 22 procedure examples

Software9

Campaigns0

None recorded.

References3

  1. CheckPoint Agrius 2023 Open source
    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.
  2. Microsoft Iran Cyber 2023 Open source
    Microsoft Threat Intelligence. (2023, May 2). Iran turning to cyber-enabled influence operations for greater effect. Retrieved May 21, 2024.
  3. SentinelOne Agrius 2021 Open source
    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.