logo

evol-agrius.pdf

ID: 3afd01ca-f5aa-4bd8-a896-40cdbbc7bff5

STIX ID: report--3afd01ca-f5aa-4bd8-a896-40cdbbc7bff5

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2021-05-25

Last Modified Date: 2021-05-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SentinelLabs details Agrius, a suspected Iran-linked threat actor active since 2020 that shifted from espionage to destructive operations against Israeli and regional targets, using custom tools (IPsec Helper backdoor, Apostle wiper/ransomware) and the DEADWOOD wiper; the report includes technical analysis, attack lifecycle, IOCs (samples, mutexes, service names, C2 URLs, IPs), YARA detections, and mitigation-relevant TTPs.