Jennlog and Apostle: Unpacking Agrius's Ransomware Attack on Israeli Academia
- Actor Motivations: Extortion,Sabotage
- Attack Vectors: Ransomware,RAT
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Apostle ransomware was resurrected in a targeted attack by Agrius against Bar-Ilan University in Israel. The report details the use of a custom loader, Jennlog, to obfuscate, encrypt, and compress the ransomware. Jennlog disguises the payload within seemingly innocuous log files and conducts environment checks to evade detection. This version of Apostle, compiled on the day of the attack, encrypts victim data, demanding a ransom and altering desktop wallpapers to display a clown image. Additionally, another Jennlog variant was found loading OrcusRAT, indicating broader malicious capabilities of the threat actor.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Bar-Ilan University Bar-Ilan University is a public research university in the Tel Aviv District city of Ramat Gan, Israel. Established in 1955, Bar Ilan is Israel's second-largest academic institution. It has about 20,000 students and 1,350 faculty members. Bar-Ilan University has been targeted by Agrius as the main target. | Verified |
| Sector | University | Verified |
| Region | Israel | Verified |
Extracted IOCs
- 43b810f918e357669be42030a1feb727
- 5e5e526a69490399494dcd7195bb6c67
- add7b6b60e746c36a66f5ec233873372
- fc8221382521a40ec0042431a947a3ca
- 3de36410a99cf3bd8e0c56fdeafa32bbf7625af1
- a35bffc49871bb3a48bdd35b4a4d04d208f23487
- c9428afa269bbf8c48a08a7109c553163d2051e7
- cbdbda089f7c7840d4daed22c34969fd876315b6
- 069686119adc13e1785cb7a425611d1ec13f33ae75962a7e50e00414209d1809
- 0ba324337b1d76a5afc26956d4dc9f57786483230112eaead5b5c92022c089c7
- 14659857df1753f720ac797a43a9c3f3e241c3df762de7f50bbbae00feb818c9
- 44c13c46d4f597ea0625f1c87eecffe3cd5dcd257c5fac18a6fa931ba9b5f97a
Tip: 12 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 12 file hash) to this threat have been found.
FAQs
Agrius Threat Actor & Apostle Ransomware
A university was targeted in a cyberattack where malicious software locked down computer systems. The attackers left a ransom demand text file on the affected computers and changed the desktop backgrounds to a picture of a clown.
The attack is suspected to be the work of Agrius, a threat actor based in Iran. This group operates primarily in the Middle East and has a history of conducting destructive cyberattacks.
The incident was a ransomware attack intended to extort the victim. The attackers used a custom-built ransomware program called "Apostle" to achieve this goal.
Yes, the higher education sector was specifically targeted in this incident. The only publicly identified victim of this specific ransomware deployment is Bar-Ilan, an Israeli university.
The attackers used a custom tool called "Jennlog" to hide their ransomware inside files designed to look like normal computer logs. Before launching the ransomware, this tool checked the computer to ensure it was the correct target and not a security researcher's testing environment.
This appears to be a highly targeted attack. The malicious software includes specific configuration checks to ensure it only runs on a predetermined computer system, and it will automatically delete itself if it lands on the wrong machine.
While the report does not detail broad defensive strategies, organizations can protect themselves by monitoring for files that disguise themselves as standard logs. Additionally, security teams should watch for automated scripts that attempt to delete files or programs after they run.