Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.4
group
Agrius G1030
- Created
- 21 May 2024
- Last modified
- 31 July 2026
- Aliases
- Agrius · Pink Sandstorm · AMERICIUM · Agonizing Serpens · BlackShadow
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.[1][2] Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).[3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1030
Agrius dumped the SAM file on victim machines to capture credentials.5
Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.6
Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.7
Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts.8 Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.9
Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.10
Standing G1030
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
57th percentile · 57% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
73rd percentile · 73% of 176 ATT&CK groups have this many tactics spanned or fewer.
81st percentile · 81% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
84th percentile · 84% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1030
1158 distinct rules cover the 22 techniques recorded for this group. The 1239 technique-to-rule mappings resolve to 1158 distinct rules, because one rule can cover several techniques. 715 Sigma · 443 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org