Moses Staff
Named by self givenSuspected state sponsor: Islamic Republic of IranMoses Staff is an Iranian MOIS-linked hacktivist group that emerged in September 2021, conducting destructive cyberattacks and data theft exclusively against Israeli organizations across government, military, finance, and IT sectors. The group uses wiper malware disguised as ransomware — including the PyDCrypt encryptor and DCSrv tool — combined with public data leaks to maximize political and psychological impact. Moses Staff is tracked as Cobalt Sapling by Secureworks and DEV-0500/Marigold Sandstorm by Microsoft. The Abraham's Ax persona represents a related operation targeting Saudi Arabian organizations.
Targeted Regions
ChileChile
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
GermanyGermany
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
IndiaIndia
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
IsraelIsrael
Dec 2020 ~ Feb 2022
Dec 2020 ~ Feb 2022
Sep 2021 ~ Nov 2021 Dec 2020 ~ Feb 2022 Oct 2021 ~ Feb 2022
Sep 2021 ~ Nov 2021 Dec 2020 ~ Feb 2022 Oct 2021 ~ Feb 2022
Dec 2020 ~ Feb 2022 Oct 2021 ~ Feb 2022
ItalyItaly
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
TurkeyTurkey
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
United Arab EmiratesUnited Arab Emirates
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
United StatesUnited States
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.