Pink Sandstorm is an Iranian-linked APT group known for destructive wiper attacks targeting Israeli education and technology sectors.
Analyst brief
Pink Sandstorm (also known as Agonizing Serpens) is an Iranian-linked APT group active since 2020, notorious for destructive wiper and fake ransomware attacks. They primarily target Israeli organizations in the education and technology sectors, aiming to steal sensitive data (PII, intellectual property) and inflict damage by wiping endpoints. Key TTPs include exploitation of public-facing applications for initial access, deployment of custom malware like MultiLayer Wiper and Apostle, password spraying, credential access via Mimikatz and SAM database, and lateral movement using RDP over C2 channels. Defenders should prioritize patching public-facing applications, monitoring for web shell activity (e.g., ASPXSpy), anomalous RDP sessions, and signs of data staging and exfiltration to detect this group's operations.
Pink Sandstorm
AMERICIUMBlackShadowDEV-0022
unknown
Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, primarily targeting Israeli organizations in the education and technology sectors. The group has strong connections to Iran's Ministry of Intelligence and Security and has been observed using various tools and techniques to bypass security measures. They aim to steal sensitive information, including PII and intellectual property, and inflict damage by wiping endpoints.