Apostle
MITRE ATT&CK: S1133 View on attack.mitre.org
Aliases: Apostle
- Malware type
- wiper, ransomware
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-05-29 20:55:56
- Profile updated
- 2026-07-07 13:11:44
Targeted industries: government-and-public-sector
Targeted regions: country_code:ir
Context
Apostle is malware that has functioned as both a wiper and, in more recent versions, as ransomware. Apostle is written in .NET and shares various programming and functional overlaps with IPsec Helper.
Detection coverage
- 2 YARA rules
- 108 Sigma rules
Malware & tools used
- Clear Windows Event Logs (attack-pattern)
- Process Discovery (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Execution Guardrails (attack-pattern)
- Scheduled Task (attack-pattern)
- Disk Content Wipe (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Data Destruction (attack-pattern)
- File Deletion (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Agrius (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Apostle (yara-rule)
- SEKOIA_Loader_Win_Jennlog (yara-rule)
Reports & references
- Palo Alto Unit 42 — Agonizing Serpens Targets Israeli Tech Higher Ed Sectors (report)
- assets.sentinelone.com — Evol Agrius (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Apostle (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
- sentinelone.com — Sentinellabs From Wiper To Ransomware The Evolution Of Agrius (report)
- sentinelone.com — New Version Of Apostle Ransomware Reemerges In Targeted Attack On Higher Education (report)
- cyberpunkleigh.wordpress.com — Apostle Ransomware Analysis (report)
- ESET — Fantasy New Agrius Wiper Supply Chain Attack (report)
- MITRE ATT&CK — S1133 (report)