Çeteler
B

Blackshadow

Pasif

Agrius · Pink Sandstorm · AMERICIUM olarak da bilinir

Toplam kurban

0

Bu ay

0

Aktif

—

DayBreach AI istihbaratı

Çete profili ve güncel haberler · web kaynaklı

Yükleniyor…

Nasıl çalışıyor

BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.

T1018 · Remote System DiscoveryT1685 · Disable or Modify ToolsT1046 · Network Service DiscoveryT1078.002 · Domain AccountsT1140 · Deobfuscate/Decode Files or InformationT1505.003 · Web ShellT1005 · Data from Local SystemT1583 · Acquire InfrastructureT1074.001 · Local Data StagingT1110.003 · Password SprayingT1119 · Automated CollectionT1003.002 · Security Account ManagerT1560.001 · Archive via UtilityT1036 · MasqueradingT1003.001 · LSASS MemoryT1021.001 · Remote Desktop ProtocolT1190 · Exploit Public-Facing ApplicationT1110 · Brute ForceT1059.003 · Windows Command ShellT1543.003 · Windows ServiceT1041 · Exfiltration Over C2 ChannelT1570 · Lateral Tool Transfer

MITRE ATT&CK profili

G1030

[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked [Agrius](https://attack.mitre.org/groups/G1030) to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)

MITRE

İlişkili zararlı yazılımlar ve araçlar

NBTscanMimikatzIPsec HelperMoneybirdMultiLayer WiperDEADWOODBFG AgonizerASPXSpyApostle