Israeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,Keylogger
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
The Moses Staff group has been orchestrating cyber attacks on various Israeli organizations since late 2020, using sophisticated tools and methodologies. Their primary mode of intrusion involved leveraging the ProxyShell exploit in Microsoft Exchange servers. Once in, they deployed two web shells and a complex backdoor mechanism, largely aimed at data exfiltration. Despite focusing primarily on espionage, the group's capabilities hint at potential for destructive attacks. The use of a hardcoded ID in the backdoor binary indicates that attacks may be personalized per target.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Israel | Verified |
Extracted IOCs
- techzenspace[.]com
- 2ac7df27bbb911f8aa52efcf67c5dc0e869fcd31ff79e86b6bd72063992ea8ad
- cafa8038ea7e46860c805da5c8c1aa38da070fa7d540f4b41d5e7391aa9a8079
- ff15558085d30f38bc6fd915ab3386b59ee5bb655cbccbeb75d021fdd1fde3ac
- 87[.]120.8.210
- hxxp://87[.]120.8.210:80/rvp/index3[.]php
- hxxp://techzenspace[.]com:80/rvp/index8.php
Tip: 7 related IOCs (1 IP, 1 domain, 2 URL, 0 email, 3 file hash) to this threat have been found.
Overlaps
Source: Secureworks - January 2023
Detection (two cases): cafa8038ea7e46860c805da5c8c1aa38da070fa7d540f4b41d5e7391aa9a8079, ff15558085d30f38bc6fd915ab3386b59ee5bb655cbccbeb75d021fdd1fde3ac
Source: Cybereason - February 2022
Detection (two cases): 87[.]120.8.210, techzenspace[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: Moses Staff Cyberattacks Against Israeli Organizations
Moses Staff, an Iran-linked threat group, conducted a long-running espionage campaign against Israeli organizations. The attackers broke into targets through a known vulnerability in Microsoft Exchange servers, then deployed a custom set of malicious tools to maintain access, steal data, and monitor victims. The campaign ran largely undetected for over a year before being publicly reported by Fortinet in February 2022.
The attacks are attributed to Moses Staff, a threat group believed to be sponsored by the Iranian government. The group has a history of targeting Israeli entities and combines espionage with the potential for destructive follow-on operations. Their tools and web shell artifacts match previously documented Moses Staff activity reported by Check Point Research and Cybereason.
The campaign was primarily aimed at espionage and data theft. Attackers focused on exfiltrating sensitive files — including email archives — from compromised Exchange servers, harvesting credentials, and maintaining persistent, covert access. While the observed attacks stopped short of destructive action, the capabilities deployed suggest the group could pivot to sabotage if directed to do so.
The targeting was narrowly focused on Israel. All confirmed victims were Israeli organizations, and all network traffic to the attacker-controlled servers originated from Israeli IP addresses. A significant spike in C2 activity was observed in April 2021, suggesting the campaign was most active during that period, though it began as early as late 2020.
All identified targets were Israeli organizations across multiple industries. Fortinet notes that victims spanned various sectors, though specifics were not disclosed. The campaign did not appear to focus on a single vertical — rather, the shared factor among targets was their geographic location and potential intelligence value to the Iranian state.
Attackers first exploited the ProxyShell vulnerability in Microsoft Exchange to gain a foothold, then planted two web shells to maintain remote access. They dumped Windows login credentials, exfiltrated email files, and installed a multi-part backdoor called DriveGuard. This backdoor received commands from attacker-controlled servers, could capture screenshots, log keystrokes, transfer files, and even self-destruct. A watchdog component injected into a system process ensured the backdoor stayed running even after reboots or detection attempts.
Israeli organizations represent high-value intelligence targets for Iranian state-aligned actors, given the ongoing geopolitical tensions between the two countries. Access to Israeli government, defense, and commercial networks provides Iran with potential strategic intelligence. The group's use of per-target backdoor variants also suggests pre-operational research and deliberate selection of victims rather than opportunistic scanning.
Organizations should ensure all Microsoft Exchange servers are fully patched, especially against ProxyShell vulnerabilities. Security teams should review IIS directories for unexpected web shell files and monitor for unusual scheduled tasks or services named after legitimate software. Enabling endpoint detection tools to flag LSASS memory access and unexpected process injection activity is strongly recommended. Blocking outbound HTTP connections to unknown or low-reputation domains, particularly those using PHP endpoints, can also help disrupt backdoor communications.