Blackshadow
PasifAgrius · Pink Sandstorm · AMERICIUM olarak da bilinir
Toplam kurban
0
Bu ay
0
Aktif
—
DayBreach AI istihbaratı
Nasıl çalışıyor
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.
MITRE ATT&CK profili
G1030
[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: SentinelOne Agrius 2021)(Citation: CheckPoint Agrius 2023) Public reporting has linked [Agrius](https://attack.mitre.org/groups/G1030) to Iran's Ministry of Intelligence and Security (MOIS).(Citation: Microsoft Iran Cyber 2023)
Kullandığı teknikler
Remote System Discovery
T1685Disable or Modify Tools
T1046Network Service Discovery
T1078.002Domain Accounts
T1140Deobfuscate/Decode Files or Information
T1505.003Web Shell
T1005Data from Local System
T1583Acquire Infrastructure
T1074.001Local Data Staging
T1110.003Password Spraying
T1119Automated Collection
T1003.002Security Account Manager
T1560.001Archive via Utility
T1036Masquerading
T1003.001LSASS Memory
T1021.001Remote Desktop Protocol
İlişkili zararlı yazılımlar ve araçlar