Apostle

S1133

Malware.View on attack.mitre.org

About this malware

Apostle is malware that has functioned as both a wiper and, in more recent versions, as ransomware. Apostle is written in .NET and shares various programming and functional overlaps with IPsec Helper.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1053.005
Scheduled Task

Apostle achieves persistence by creating a scheduled task, such as MicrosoftCrashHandlerUAC.

T1057
Process Discovery

Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files.

T1070.004
File Deletion

Apostle writes batch scripts to disk, such as system.bat and remover.bat, that perform various anti-analysis and anti-forensic tasks, before finally deleting themselves at the end of execution. Apostle attempts to delete itself after encryption or wiping operations are complete and before shutting down the victim machine.

T1140
Deobfuscate/Decode Files or Information

Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims.

T1480
Execution Guardrails

Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function.

T1485
Data Destruction

Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, wiper-action. Apostle writes random data to original files after an encrypted copy is created, along with resizing the original file to zero and changing time property metadata before finally deleting the original file.

T1486
Data Encrypted for Impact

Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension.

T1529
System Shutdown/Reboot

Apostle reboots the victim machine following wiping and related activity.

T1561.001
Disk Content Wipe

Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity.

T1685.005
Clear Windows Event Logs

Apostle will attempt to delete all event logs on a victim machine following file wipe activity.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SentinelOne Agrius 2021 Open source
    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.