Threats Feed|Moses Staff|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date15/02/2022

Israeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Keylogger
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Moses Staff group has been orchestrating cyber attacks on various Israeli organizations since late 2020, using sophisticated tools and methodologies. Their primary mode of intrusion involved leveraging the ProxyShell exploit in Microsoft Exchange servers. Once in, they deployed two web shells and a complex backdoor mechanism, largely aimed at data exfiltration. Despite focusing primarily on espionage, the group's capabilities hint at potential for destructive attacks. The use of a hardcoded ID in the backdoor binary indicates that attacks may be personalized per target.

Detected Targets

TypeDescriptionConfidence
RegionIsrael
Verified

Extracted IOCs

  • techzenspace[.]com
  • 2ac7df27bbb911f8aa52efcf67c5dc0e869fcd31ff79e86b6bd72063992ea8ad
  • cafa8038ea7e46860c805da5c8c1aa38da070fa7d540f4b41d5e7391aa9a8079
  • ff15558085d30f38bc6fd915ab3386b59ee5bb655cbccbeb75d021fdd1fde3ac
  • 87[.]120.8.210
  • hxxp://87[.]120.8.210:80/rvp/index3[.]php
  • hxxp://techzenspace[.]com:80/rvp/index8.php
download

Tip: 7 related IOCs (1 IP, 1 domain, 2 URL, 0 email, 3 file hash) to this threat have been found.

Overlaps

Cobalt SaplingUnmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations

Source: Secureworks - January 2023

Detection (two cases): cafa8038ea7e46860c805da5c8c1aa38da070fa7d540f4b41d5e7391aa9a8079, ff15558085d30f38bc6fd915ab3386b59ee5bb655cbccbeb75d021fdd1fde3ac

Moses StaffStrifeWater: Unmasking the New RAT Deployed by Iranian APT Moses Staff

Source: Cybereason - February 2022

Detection (two cases): 87[.]120.8.210, techzenspace[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: Moses Staff Cyberattacks Against Israeli Organizations

Moses Staff, an Iran-linked threat group, conducted a long-running espionage campaign against Israeli organizations. The attackers broke into targets through a known vulnerability in Microsoft Exchange servers, then deployed a custom set of malicious tools to maintain access, steal data, and monitor victims. The campaign ran largely undetected for over a year before being publicly reported by Fortinet in February 2022.

The attacks are attributed to Moses Staff, a threat group believed to be sponsored by the Iranian government. The group has a history of targeting Israeli entities and combines espionage with the potential for destructive follow-on operations. Their tools and web shell artifacts match previously documented Moses Staff activity reported by Check Point Research and Cybereason.

The campaign was primarily aimed at espionage and data theft. Attackers focused on exfiltrating sensitive files — including email archives — from compromised Exchange servers, harvesting credentials, and maintaining persistent, covert access. While the observed attacks stopped short of destructive action, the capabilities deployed suggest the group could pivot to sabotage if directed to do so.

The targeting was narrowly focused on Israel. All confirmed victims were Israeli organizations, and all network traffic to the attacker-controlled servers originated from Israeli IP addresses. A significant spike in C2 activity was observed in April 2021, suggesting the campaign was most active during that period, though it began as early as late 2020.

All identified targets were Israeli organizations across multiple industries. Fortinet notes that victims spanned various sectors, though specifics were not disclosed. The campaign did not appear to focus on a single vertical — rather, the shared factor among targets was their geographic location and potential intelligence value to the Iranian state.

Attackers first exploited the ProxyShell vulnerability in Microsoft Exchange to gain a foothold, then planted two web shells to maintain remote access. They dumped Windows login credentials, exfiltrated email files, and installed a multi-part backdoor called DriveGuard. This backdoor received commands from attacker-controlled servers, could capture screenshots, log keystrokes, transfer files, and even self-destruct. A watchdog component injected into a system process ensured the backdoor stayed running even after reboots or detection attempts.

Israeli organizations represent high-value intelligence targets for Iranian state-aligned actors, given the ongoing geopolitical tensions between the two countries. Access to Israeli government, defense, and commercial networks provides Iran with potential strategic intelligence. The group's use of per-target backdoor variants also suggests pre-operational research and deliberate selection of victims rather than opportunistic scanning.

Organizations should ensure all Microsoft Exchange servers are fully patched, especially against ProxyShell vulnerabilities. Security teams should review IIS directories for unexpected web shell files and monitor for unusual scheduled tasks or services named after legitimate software. Enabling endpoint detection tools to flag LSASS memory access and unexpected process injection activity is strongly recommended. Blocking outbound HTTP connections to unknown or low-reputation domains, particularly those using PHP endpoints, can also help disrupt backdoor communications.

About Affiliation
Moses Staff
Moses Staff is an Iranian MOIS-linked hacktivist group that emerged in September 2021, conducting destructive cyberattacks and data theft exclusively against Israeli organizations across government, military, finance, and IT sectors. The group uses wiper malware disguised as ransomware — including the PyDCrypt encryptor and DCSrv tool — combined with public data leaks to maximize political and psychological impact. Moses Staff is tracked as Cobalt Sapling by Secureworks and DEV-0500/Marigold Sandstorm by Microsoft. The Abraham's Ax persona represents a related operation targeting Saudi Arabian organizations.
View Moses Staff's Insights