Threats Feed|Agrius|Last Updated 24/07/2026|AuthorCertfa Radar|Publish Date30/09/2021

Jennlog and Apostle: Unpacking Agrius's Ransomware Attack on Israeli Academia

  • Actor Motivations: Extortion,Sabotage
  • Attack Vectors: Ransomware,RAT
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Apostle ransomware was resurrected in a targeted attack by Agrius against Bar-Ilan University in Israel. The report details the use of a custom loader, Jennlog, to obfuscate, encrypt, and compress the ransomware. Jennlog disguises the payload within seemingly innocuous log files and conducts environment checks to evade detection. This version of Apostle, compiled on the day of the attack, encrypts victim data, demanding a ransom and altering desktop wallpapers to display a clown image. Additionally, another Jennlog variant was found loading OrcusRAT, indicating broader malicious capabilities of the threat actor.

Detected Targets

TypeDescriptionConfidence
CaseBar-Ilan University
Bar-Ilan University is a public research university in the Tel Aviv District city of Ramat Gan, Israel. Established in 1955, Bar Ilan is Israel's second-largest academic institution. It has about 20,000 students and 1,350 faculty members. Bar-Ilan University has been targeted by Agrius as the main target.
Verified
SectorUniversity
Verified
RegionIsrael
Verified

Extracted IOCs

  • 43b810f918e357669be42030a1feb727
  • 5e5e526a69490399494dcd7195bb6c67
  • add7b6b60e746c36a66f5ec233873372
  • fc8221382521a40ec0042431a947a3ca
  • 3de36410a99cf3bd8e0c56fdeafa32bbf7625af1
  • a35bffc49871bb3a48bdd35b4a4d04d208f23487
  • c9428afa269bbf8c48a08a7109c553163d2051e7
  • cbdbda089f7c7840d4daed22c34969fd876315b6
  • 069686119adc13e1785cb7a425611d1ec13f33ae75962a7e50e00414209d1809
  • 0ba324337b1d76a5afc26956d4dc9f57786483230112eaead5b5c92022c089c7
  • 14659857df1753f720ac797a43a9c3f3e241c3df762de7f50bbbae00feb818c9
  • 44c13c46d4f597ea0625f1c87eecffe3cd5dcd257c5fac18a6fa931ba9b5f97a
download

Tip: 12 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 12 file hash) to this threat have been found.

FAQs

Agrius Threat Actor & Apostle Ransomware

A university was targeted in a cyberattack where malicious software locked down computer systems. The attackers left a ransom demand text file on the affected computers and changed the desktop backgrounds to a picture of a clown.

The attack is suspected to be the work of Agrius, a threat actor based in Iran. This group operates primarily in the Middle East and has a history of conducting destructive cyberattacks.

The incident was a ransomware attack intended to extort the victim. The attackers used a custom-built ransomware program called "Apostle" to achieve this goal.

Yes, the higher education sector was specifically targeted in this incident. The only publicly identified victim of this specific ransomware deployment is Bar-Ilan, an Israeli university.

The attackers used a custom tool called "Jennlog" to hide their ransomware inside files designed to look like normal computer logs. Before launching the ransomware, this tool checked the computer to ensure it was the correct target and not a security researcher's testing environment.

This appears to be a highly targeted attack. The malicious software includes specific configuration checks to ensure it only runs on a predetermined computer system, and it will automatically delete itself if it lands on the wrong machine.

While the report does not detail broad defensive strategies, organizations can protect themselves by monitoring for files that disguise themselves as standard logs. Additionally, security teams should watch for automated scripts that attempt to delete files or programs after they run.

About Affiliation
Agrius
Agrius is an Iranian state-linked threat actor active since at least 2020, assessed by multiple vendors to operate on behalf of Iran's Ministry of Intelligence and Security (MOIS). The group is best known for destructive wiper and fake-ransomware campaigns aimed primarily at Israeli organizations across the technology, education, insurance, and healthcare sectors. Agrius gains initial access by exploiting public-facing web applications, deploys ASPXSpy-based web shells for persistence, and ultimately delivers custom wipers such as Apostle and DEADWOOD to destroy data and disrupt operations. Microsoft tracks the same cluster as Pink Sandstorm and AMERICIUM.
View Agrius's Insights