The Iranian-affiliated group dedicated exclusively to destructive operations has the diamond industry supply chain as its primary objective
ESET, a global leader in the cybersecurity market, has discovered a new wiper and its execution tool, both attributable to the Iranian-affiliated APT Agrius group. The malware authors conducted a supply-chain attack by leveraging an Israeli software developer to distribute both the new wiper called Fantasy and Sandals, a lateral movement and wiper execution tool. The hacked Israeli software suite is used in the diamond industry. In February 2022, Agrius expanded its scope to target an Israeli human resources company, a diamond wholesaler and an IT consultancy firm. The group is known for its destructive activities. Victims have also been observed in South Africa and Hong Kong.
"The attack lasted less than three hours and during this time ESET customers were already protected with detections that identified Fantasy as a wiper and blocked it from running. We observed that the software developer deployed secure updates within hours of the attack," he explained Adam Burgher, Senior Threat Intelligence Analyst di ESET. ESET attempted to contact the software developer to inform them of a potential compromise, but received no response.
"On February 20, 2022, Agrius deployed credential harvesting tools to a diamond industry organization in South Africa, likely in preparation for this campaign. Then, on March 12, 2022, Agrius launched the wiping attack by distributing Fantasy and Sandals, first to the victim in South Africa, then to targets in Israel, and finally to a company in Hong Kong," Burgher clarified.
Fantasy wiper erases all files on the disk or all files in a list of 682 extensions, including file name extensions for Microsoft 365 applications such as Microsoft Word, Microsoft PowerPoint, and Microsoft Excel, and for common video, audio, and image file formats. Although the malware takes steps to make recovery and forensic analysis more difficult, it appears that recovering your Windows OS drive is possible. In fact, it was observed that the victims were back operational within a few hours.
Agrius is an Iranian-affiliated group that has been targeting Israel and the United Arab Emirates since 2020. The group initially deployed Apostle, a wiper that was initially disguised as ransomware, but later transformed into full-fledged ransomware. Agrius exploits known vulnerabilities in Internet applications to install webshells, then performs internal reconnaissance before moving laterally and delivering malicious payloads.
Since its discovery in 2021, Agrius has focused exclusively on destructive operations. Fantasy is similar in many respects to Agrius' previous wiper, Apostle, and does not apply any procedures to disguise itself as ransomware. There are only a few small changes between many of the original Apostle features and the Fantasy implementation.
For more technical information on the Agrius Fantasy wiper, please see the blog Fantasy – a new Agrius wiper deployed through a supply-chain attack su WeLiveSecurity.






