IR
Pink SandstormPink Sandstorm
Also known as: AMERICIUM · BlackShadow · DEV-0022 · Agrius · Agonizing Serpens · UNC2428 · Black Shadow · SPECTRAL KITTEN · Pink Sandstorm
Origin
IR
Known aliases
9
Profile
Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, primarily targeting Israeli organizations in the education and technology sectors. The group has strong connections to Iran's Ministry of Intelligence and Security and has been observed using various tools and techniques to bypass security measures. They aim to steal sensitive information, including PII and intellectual property, and inflict damage by wiping endpoints.
Aliases· 9
AMERICIUMBlackShadowDEV-0022AgriusAgonizing SerpensUNC2428Black ShadowSPECTRAL KITTENPink Sandstorm
References
- https://www.oodaloop.com/archive/2024/01/02/critical-infrastructure-remains-the-brass-ring-for-cyber-attackers-in-2024/
- https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/
- https://socprime.com/blog/agonizing-serpens-attack-detection-iran-backed-hackers-target-israeli-tech-firms-and-educational-institutions/
- https://therecord.media/iran-linked-hackers-target-israel-education-tech-sectors
- https://www.enigmasoftware.com/moneybirdransomware-removal/
- https://research.checkpoint.com/2023/agrius-deploys-moneybird-in-targeted-attacks-against-israeli-organizations/
- https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.