evol-agrius.pdf
ID: 3afd01ca-f5aa-4bd8-a896-40cdbbc7bff5
STIX ID: report--3afd01ca-f5aa-4bd8-a896-40cdbbc7bff5
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2021-05-25
Last Modified Date: 2021-05-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SentinelLabs details Agrius, a suspected Iran-linked threat actor active since 2020 that shifted from espionage to destructive operations against Israeli and regional targets, using custom tools (IPsec Helper backdoor, Apostle wiper/ransomware) and the DEADWOOD wiper; the report includes technical analysis, attack lifecycle, IOCs (samples, mutexes, service names, C2 URLs, IPs), YARA detections, and mitigation-relevant TTPs.
