{"id":3102,"date":"2021-06-15T20:22:48","date_gmt":"2021-06-16T01:22:48","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3102"},"modified":"2021-06-15T20:22:48","modified_gmt":"2021-06-16T01:22:48","slug":"apostle-information-cleansing-threat-and-ransomware","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/","title":{"rendered":"Apostle &#8211; Information cleansing threat and ransomware"},"content":{"rendered":"\n<p>The Apostle Malware is an interesting threat that was first detected on compromised networks of Israeli users and companies. The strange threat appears to be designed to function as a disk cleaner, but due to bugs in its code, it was unable to fully carry out its attack. Researchers who identified and analyzed the threat report that its authors refer to it as a &#8220;cleanup action,&#8221; another indication that the original purpose of the malware was to clean the victim&#8217;s disk<\/p>\n\n\n\n<p>In a post published Tuesday, SentinelOne researchers said they had determined with great confidence that based on the code and servers Apostle reported to, the malware was being used by a newly discovered group with ties to the Iranian government. While a ransomware note that the researchers recovered suggested that Apostle had been used against a critical facility in the UAE, the primary target was Israel.<\/p>\n\n\n\n<p>While the early Apostle Malware samples didn&#8217;t do their job due to bugs, recent payload updates appear to be fixed. However, the &#8216;fixes&#8217; that the criminals applied also changed the functionality of Apostle: it is now a fully developed ransomware threat, demanding money from its victims.<\/p>\n\n\n\n<p>The implementation of the encryption functionality is believed to be there to mask its real intention: Which is to destroy the victim&#8217;s data, Apostle has a major code overlay with a backdoor, called the IPSec Helper, which Agrius also uses. IPSec Helper receives a series of commands, such as downloading and running an executable file, that are issued from the attacker&#8217;s control server. Both Apostle and IPSec Helper are written in the .Net language.<\/p>\n\n\n\n<p>The development and spread of Apostle Malware is attributed to the Agrius Advanced Persistent Threat (APT) group, an emerging cybercrime organization believed to have ties to the Iranian government. This information is not a surprise considering that the main targets of Agrius are in Israel. Unfortunately, being a new threat, not much is known yet and the safest thing is that they update it and improve sooner than we think.<\/p>\n\n\n\n<p>More reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/history-of-ransomware-and-how-it-has-evolved\/\">History of Ransomware and how it has evolved<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/\">Epsilon Red Ransomware targeting Microsoft<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Apostle Malware is an interesting threat that was first detected on compromised networks of Israeli users and companies. The strange threat appears to be designed to function as a disk cleaner, but due to bugs in its code, it was unable to fully carry out its attack. Researchers who identified and analyzed the threat [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3103,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,16],"tags":[36,35,105],"class_list":["post-3102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-ransomware","tag-cybersecurity","tag-malware","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apostle - Information cleansing threat and ransomware - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"It is worrying how malware, ransomware, etc, are updated and improved so quickly and this is the case with the threat called Apostle.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apostle - Information cleansing threat and ransomware - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"It is worrying how malware, ransomware, etc, are updated and improved so quickly and this is the case with the threat called Apostle.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-16T01:22:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Apostle.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"860\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Apostle &#8211; Information cleansing threat and ransomware\",\"datePublished\":\"2021-06-16T01:22:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/\"},\"wordCount\":363,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Apostle.jpg\",\"keywords\":[\"Cybersecurity\",\"Malware\",\"Ransomware\"],\"articleSection\":[\"Cybersecurity\",\"Ransomware\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/\",\"name\":\"Apostle - Information cleansing threat and ransomware - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Apostle.jpg\",\"datePublished\":\"2021-06-16T01:22:48+00:00\",\"description\":\"It is worrying how malware, ransomware, etc, are updated and improved so quickly and this is the case with the threat called Apostle.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Apostle.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Apostle.jpg\",\"width\":1500,\"height\":860},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apostle-information-cleansing-threat-and-ransomware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apostle &#8211; Information cleansing threat and ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apostle - Information cleansing threat and ransomware - Truxgo Server Blog","description":"It is worrying how malware, ransomware, etc, are updated and improved so quickly and this is the case with the threat called Apostle.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/","og_locale":"es_MX","og_type":"article","og_title":"Apostle - Information cleansing threat and ransomware - Truxgo Server Blog","og_description":"It is worrying how malware, ransomware, etc, are updated and improved so quickly and this is the case with the threat called Apostle.....","og_url":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-16T01:22:48+00:00","og_image":[{"width":1500,"height":860,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Apostle.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Apostle &#8211; Information cleansing threat and ransomware","datePublished":"2021-06-16T01:22:48+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/"},"wordCount":363,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Apostle.jpg","keywords":["Cybersecurity","Malware","Ransomware"],"articleSection":["Cybersecurity","Ransomware"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/","url":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/","name":"Apostle - Information cleansing threat and ransomware - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Apostle.jpg","datePublished":"2021-06-16T01:22:48+00:00","description":"It is worrying how malware, ransomware, etc, are updated and improved so quickly and this is the case with the threat called Apostle.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Apostle.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Apostle.jpg","width":1500,"height":860},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/apostle-information-cleansing-threat-and-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Apostle &#8211; Information cleansing threat and ransomware"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3102"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3102\/revisions"}],"predecessor-version":[{"id":3107,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3102\/revisions\/3107"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3103"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}