SentinelLabs reported that suspected Iranian threat actor Agrius likely carried out a targeted ransomware attack against Israel’s Bar-Ilan University using a new version of its custom Apostle malware. Researchers linked the incident to an Apostle sample compiled on the same day as the attack and said the ransom note matched the note publicly associated with the university breach, strengthening attribution to the group.
The operation used a .NET loader dubbed Jennlog, which concealed payloads inside fake log-file resources, applied anti-analysis techniques, optionally checked victim fingerprints, and then decrypted and executed malware directly in memory. SentinelLabs also identified another Jennlog variant delivering OrcusRAT, indicating Agrius was continuing to refine its tooling from earlier destructive activity toward more mature ransomware-capable operations while retaining sabotage-oriented tradecraft.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs published research attributing the Bar-Ilan University incident to Agrius and detailing the use of Jennlog and Apostle. The report also noted another Jennlog variant used to load OrcusRAT, indicating continued evolution of the group’s tooling.
Researchers linked the Bar-Ilan incident to an Apostle sample compiled on August 15, 2021, the same day as the attack. The attack chain used a .NET loader dubbed Jennlog to decrypt and execute the embedded malware in memory.
SentinelLabs reported that a suspected Iranian threat actor, Agrius, likely conducted a ransomware attack against Israel’s Bar-Ilan University using a new version of its custom Apostle ransomware. The ransom note matched the note publicly associated with the incident.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.