Malware.View on attack.mitre.org
Apostle is malware that has functioned as both a wiper and, in more recent versions, as ransomware. Apostle is written in .NET and shares various programming and functional overlaps with IPsec Helper.
| Technique | Procedure example |
|---|---|
| T1053.005 Scheduled Task |
Apostle achieves persistence by creating a scheduled task, such as |
| T1057 Process Discovery |
Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. |
| T1070.004 File Deletion |
Apostle writes batch scripts to disk, such as |
| T1140 Deobfuscate/Decode Files or Information |
Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims. |
| T1480 Execution Guardrails |
Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function. |
| T1485 Data Destruction |
Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, |
| T1486 Data Encrypted for Impact |
Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension. |
| T1529 System Shutdown/Reboot |
Apostle reboots the victim machine following wiping and related activity. |
| T1561.001 Disk Content Wipe |
Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity. |
| T1685.005 Clear Windows Event Logs |
Apostle will attempt to delete all event logs on a victim machine following file wipe activity. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.