Moses Staff Cluster
Suspected state sponsor: Islamic Republic of IranMoses Staff is an Iranian state-linked hacktivist threat cluster that emerged in September 2021, conducting politically motivated cyberattacks exclusively against Israeli organizations. The group is linked to Iran's Ministry of Intelligence and Security (MOIS) and operates at the intersection of espionage and psychological operations — combining data theft with publicly claimed destructive attacks to maximize reputational and operational damage to Israeli targets.
Targets and Goals
Moses Staff has exclusively targeted Israeli organizations across government, military, finance, energy, media, and IT sectors. The group's stated goal is political — it openly declares its purpose as harming Israeli interests — rather than financial. Operations follow a pattern of initial intrusion, data exfiltration, and then destructive payload deployment, after which stolen data is leaked publicly on the group's Telegram channel and website to amplify the psychological impact.
Tooling and Tactics
Moses Staff gains initial access by exploiting known vulnerabilities in public-facing applications, particularly Microsoft Exchange servers and web applications. The group uses custom malware including PyDCrypt (a Python-based encryptor) and DCSrv (a destructive tool that abuses the legitimate DiskCryptor driver to encrypt system volumes without providing decryption keys — effectively a wiper disguised as ransomware). Post-compromise activity includes credential dumping, network reconnaissance, and lateral movement before deploying the destructive payload. The group leaks stolen data regardless of whether the destructive payload succeeds.
Aliases
Moses Staff is tracked as Cobalt Sapling by Secureworks and DEV-0500 / Marigold Sandstorm by Microsoft. The related persona Abraham's Ax was used for a distinct but overlapping campaign targeting Saudi Arabian organizations in late 2022 and early 2023.
observatory results
Abraham's Ax
Abraham's Ax is named by self given and at the moment 0 indexed report with 14 related IOCs
Cobalt Sapling
Cobalt Sapling is named by SecureWorks and at the moment 1 indexed report with 14 related IOCs
Moses Staff
Moses Staff is named by self given and at the moment 3 indexed report with 22 related IOCs
Most Common Tactics
Targeted Regions
ChileChile
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
GermanyGermany
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
IndiaIndia
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
IsraelIsrael
Dec 2020 ~ Feb 2022
Dec 2020 ~ Feb 2022
Sep 2021 ~ Nov 2021 Dec 2020 ~ Feb 2022 Oct 2021 ~ Feb 2022
Sep 2021 ~ Nov 2021 Dec 2020 ~ Feb 2022 Oct 2021 ~ Feb 2022
Dec 2020 ~ Feb 2022 Oct 2021 ~ Feb 2022
Nov 2022 ~ Jan 2023
Nov 2022 ~ Jan 2023
ItalyItaly
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Saudi ArabiaSaudi Arabia
Nov 2022 ~ Jan 2023
Nov 2022 ~ Jan 2023
TurkeyTurkey
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
United Arab EmiratesUnited Arab Emirates
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
United StatesUnited States
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Oct 2021 ~ Feb 2022
Recent Activities
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.