Apostle is a .NET malware family associated with the Iran-linked threat actor Agrius. It was initially deployed as a destructive wiper disguised as ransomware, then later evolved into a functioning ransomware variant. Early Apostle samples were intended primarily for data destruction and lacked meaningful recovery capability, indicating sabotage rather than financial extortion as the core objective. Later variants added real file-encryption behavior and ransom-note functionality, complicating attribution and incident response by making destructive operations resemble conventional ransomware incidents.
Apostle targets Windows systems and has been used primarily against organizations in Israel, with additional reporting indicating use against at least one critical facility in the United Arab Emirates. Agrius has used Apostle in broader intrusion chains that also involved exploitation of public-facing applications, webshell deployment, credential theft and lateral movement using public offensive tools, and use of the custom IPsec Helper backdoor. Code and implementation similarities between Apostle and IPsec Helper suggest common development lineage.
Apostle supports persistence through creation of scheduled tasks using legitimate-looking names. Its destructive and ransomware-capable variants search available drives for files matching hard-coded extension lists. In ransomware-capable form, Apostle creates encrypted copies of files and deletes the originals, renaming the resulting files with randomized identifiers and a lock-style extension. In destructive mode, it overwrites original file contents with random data, truncates files, alters metadata, and deletes them, producing irreversible data loss. The malware also writes batch scripts to perform anti-analysis and anti-forensic actions, attempts to delete itself after completing encryption or wiping activity, clears Windows event logs, and reboots the victim machine to hinder recovery.
Some variants require a base64-encoded execution argument to proceed with ransomware functionality and otherwise self-delete, indicating operator-controlled execution guardrails. Apostle has also been observed delivered through a .NET loader known as Jennlog, which decrypts and executes the payload in memory and can include anti-analysis and victim-fingerprinting checks. Overall, Apostle is best understood as a state-aligned disruptive malware family that blends wiper and ransomware tradecraft to conceal politically motivated destructive operations behind the appearance of criminal extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Agrius actors also dropped a novel wiper named ‘Apostle’... Later intrusions carried out by Agrius revealed they kept maintaining and improving Apostle, turning it into a fully functional ransomware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content contains many examples of base64, XOR, RC4, AES, Rijndael, custom ciphers, rolling XOR, and multi-layer obfuscation used to hide payloads, strings, scripts, and C2 data.
The new version of Apostle is obfuscated, encrypted and compressed as a resource in a loader we call Jennlog, as it attempts to masquerade payload in resources as log files.
APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Initially engaged in espionage activity, Agrius deployed a set of destructive wiper attacks against Israeli targets, masquerading the activity as ransomware attacks.
Later intrusions carried out by Agrius revealed they kept maintaining and improving Apostle, turning it into a fully functional ransomware... In some cases, the group leveraged its access to deploy destructive wiper malware, and in others a custom ransomware.
Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. LockBit 3.0 can identify and terminate specific services. RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Originally a data wiper, later modified to operate as a ransomware variant and used in pseudo-ransomware attacks that disguise destructive activity as financial extortion.
Originally a wiper masquerading as ransomware, Apostle later evolved into functioning ransomware, blurring the line between destructive sabotage and extortion.
An Iran-linked wiper malware family identified in the content as part of a broader destructive cyber capability focused on data destruction and disruption.
Destructive wiper malware previously deployed by Iranian operators against organizations in the Middle East.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.