Adversary-emulation profile for Pink Sandstorm (G1030 / Agrius / Agonizing Serpens / AMERICIUM / BlackShadow / DEV-0227), Iran's MOIS-linked destructive wiper and pseudo-ransomware operator.
59
68%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/pink-sandstorm/SKILL.mdPink Sandstorm (MITRE ATT&CK G1030) is an Iranian threat actor active since at least 2020, linked to Iran's Ministry of Intelligence and Security (MOIS). The group is notable for a series of destructive wiper and pseudo-ransomware operations primarily targeting Israeli organizations, with secondary operations against targets in the UAE, South Africa, and Hong Kong. Agrius deliberately disguises destructive wiper attacks as ransomware, using extortion personas (BlackShadow, Moneybird, n3tw0rm) to mask its true intent — strategic disruption and data destruction aligned with Iranian state interests. The group operates a lineage of custom .NET and C++ wipers (Apostle → Fantasy → MultiLayer → BFG Agonizer) alongside the IPsec Helper backdoor, ASPXSpy web shells, and public offensive tools (Mimikatz, Plink, NBTscan). Since the October 2023 Israel-Hamas war, Microsoft has observed Pink Sandstorm collaborating with Hezbollah cyber units and escalating hack-and-leak operations against Israeli targets.
cmd.exe.systems.exe; DEADWOOD masquerades as a legitimate service (T1036.004).C:\windows\temp\s\ for exfiltration.sql.net4.exe tool automates SQL database PII extraction.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| Apostle | S1133 | .NET wiper / ransomware (evolved from wiper to dual-capability) | Custom |
| Fantasy | (no ATT&CK software ID) | Wiper built on Apostle codebase (supply-chain deployed) | Custom |
| DEADWOOD (Detbosit) | S1134 | Wiper with MBR overwrite and service masquerading | Custom |
| IPsec Helper | S1132 | Post-exploitation backdoor / RAT (HTTP C2, PowerShell, VBS) | Custom |
| MultiLayer Wiper | S1135 | Wiper with timestomping and event-log clearing | Custom |
| BFG Agonizer | S1136 | Wiper with disk-structure wipe and recovery inhibition | Custom |
| Moneybird | S1137 | C++ ransomware (AES-256-GCM, per-file keys) | Custom |
| PartialWasher | (no ATT&CK software ID) | Selective file wiper | Custom |
| Sqlextractor (sql.net4.exe) | (no ATT&CK software ID) | Custom SQL database PII extraction tool | Custom |
| ASPXSpy | S0073 | ASPX web shell (base64-encoded variants) | Public |
| Mimikatz | S0002 | Credential dumping (LSASS, SAM) | Public |
| NBTscan | S0590 | NetBIOS/SMB network scanner | Public |
| Plink | (SSH tunnel utility) | SSH tunneling for RDP (renamed systems.exe) | Public |
| WinEggDrop | (no ATT&CK software ID) | Port scanner for host enumeration | Public |
| 7zip | (archiver) | Data archiving for exfiltration staging | Public |
| WinSCP / Putty | (file transfer / SSH) | Exfiltration via SCP/SFTP to C2 | Public |
| ProtonVPN | (VPN service) | Last-hop anonymization | Public (infrastructure) |
| GMER64.sys | (anti-rootkit driver) | Abused to kill EDR/security processes | Public (LOLDriver) |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never run destructive (T1485/T1561) or wiper actions outside an explicitly sanctioned, isolated lab.
Map Pink Sandstorm's signature plays to Decepticon's own capabilities:
systems.exe to emulate the masquerading TTP) to tunnel RDP connections through the web shell. Use harvested domain credentials to move laterally to database and file servers.sql.net4.exe) to automate PII and IP extraction from in-scope databases. Stage data in C:\windows\temp\s\, archive with 7zip, and exfiltrate via WinSCP/Putty to C2 infrastructure..aspx files or suspicious text files in Certificate stores; baseline web-server child processes (w3wp.exe → cmd.exe is anomalous); deploy file-integrity monitoring on web roots; hunt for base64-encoded ASPXSpy indicators.reg save).systems.exe); restrict RDP to jump servers; alert on RDP connections originating from web server processes.vssadmin delete shadows and bcdedit /set {default} recoveryenabled No; trigger on Windows event log clearing (Event ID 1102); alert on unexpected system shutdown/reboot commands.C:\windows\temp\ for unusual archive files; alert on WinSCP/Putty/SCP outbound connections to unknown hosts; DLP monitoring for 7zip archive creation containing database dumps.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.