Threats Feed
- Public
Unmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations
Secureworks Counter Threat Unit links two separate hacktivist personas — Moses Staff and Abraham's Ax — to a single Iranian threat group tracked as COBALT SAPLING. Moses Staff emerged in September 2021, targeting Israeli companies and individuals tied to Israel's signals intelligence Unit 8200 through data theft, leaks, and destructive encryption using the PyDCrypt loader and DCSrv wiper. Abraham's Ax surfaced in November 2022, pivoting to attack Saudi Arabian government ministries — likely in response to reported Israeli-Saudi normalization efforts that Iran perceived as a regional threat. Secureworks identifies the link through overlapping infrastructure: both groups' leak sites were hosted in near-adjacent IP addresses within the same subnet at early points in their operation, a pattern assessed as highly unlikely to be coincidental. Additional shared indicators include nearly identical logo style, multilingual WordPress-based leak sites both registered through the same Swedish registrar, reused video production elements, and the same ASPX web shells used in intrusions attributed to Moses Staff. The StrifeWater RAT and DriveGuard tool have been linked to COBALT SAPLING through technical overlaps across intrusions. Malware artifacts suggest the group has been active since at least November 2020, predating the Moses Staff persona's public debut by nearly a year.
read more about Unmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations - Public
Israeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group
The Moses Staff group has been orchestrating cyber attacks on various Israeli organizations since late 2020, using sophisticated tools and methodologies. Their primary mode of intrusion involved leveraging the ProxyShell exploit in Microsoft Exchange servers. Once in, they deployed two web shells and a complex backdoor mechanism, largely aimed at data exfiltration. Despite focusing primarily on espionage, the group's capabilities hint at potential for destructive attacks. The use of a hardcoded ID in the backdoor binary indicates that attacks may be personalized per target.
read more about Israeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group - Public
StrifeWater: Unmasking the New RAT Deployed by Iranian APT Moses Staff
The Iranian APT group Moses Staff deployed a new, previously undocumented Remote Access Trojan (RAT) called StrifeWater for its cyber-espionage and disruption operations. The StrifeWater RAT has been used in initial attack stages, demonstrating various capabilities like listing system files, executing system commands, creating persistence, and downloading updates. Post-infection, it's replaced with ransomware not for financial gain but to disrupt operations and inflict system damage. Victims of these attacks span globally across countries like Israel, Italy, India, Germany, Chile, Turkey, UAE, and the US.
read more about StrifeWater: Unmasking the New RAT Deployed by Iranian APT Moses Staff - Public
Political Motivation and Damage: Understanding the MosesStaff Cyberattacks
Check Point Research documents MosesStaff, an Iranian-linked group that began targeting Israeli organizations in September 2021 with explicitly destructive intent. Unlike financially motivated ransomware groups, the actors openly stated their goal was to damage Israeli companies by leaking stolen data and permanently encrypting their networks — with no ransom demand and no decryption option offered. Initial access was gained by exploiting known vulnerabilities in internet-facing infrastructure, particularly Microsoft Exchange servers, where a password-protected web shell was deployed. Lateral movement relied on PsExec, PowerShell, and WMIC using harvested administrator credentials. The group deployed two custom tools: PyDCrypt, a Python-compiled dropper tailored per victim with hardcoded network credentials, and DCSrv, a destructive encryptor built around the open-source DiskCryptor library. DCSrv encrypted all drive volumes using AES and installed a custom bootloader that prevented systems from starting without the correct password. The encryption key was derived from a per-hostname MD5 hash function — a design flaw that Check Point notes may allow decryption under certain conditions. Attribution artifacts, including a tool submission from Palestine and image metadata tied to GMT+3, suggest a Palestinian or Israeli-adjacent operator.
read more about Political Motivation and Damage: Understanding the MosesStaff Cyberattacks