Threats Feed|Moses Staff|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date15/11/2021

Political Motivation and Damage: Understanding the MosesStaff Cyberattacks

  • Actor Motivations: Exfiltration,Sabotage
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Wiper
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Check Point Research documents MosesStaff, an Iranian-linked group that began targeting Israeli organizations in September 2021 with explicitly destructive intent. Unlike financially motivated ransomware groups, the actors openly stated their goal was to damage Israeli companies by leaking stolen data and permanently encrypting their networks — with no ransom demand and no decryption option offered. Initial access was gained by exploiting known vulnerabilities in internet-facing infrastructure, particularly Microsoft Exchange servers, where a password-protected web shell was deployed. Lateral movement relied on PsExec, PowerShell, and WMIC using harvested administrator credentials. The group deployed two custom tools: PyDCrypt, a Python-compiled dropper tailored per victim with hardcoded network credentials, and DCSrv, a destructive encryptor built around the open-source DiskCryptor library. DCSrv encrypted all drive volumes using AES and installed a custom bootloader that prevented systems from starting without the correct password. The encryption key was derived from a per-hostname MD5 hash function — a design flaw that Check Point notes may allow decryption under certain conditions. Attribution artifacts, including a tool submission from Palestine and image metadata tied to GMT+3, suggest a Palestinian or Israeli-adjacent operator.

Detected Targets

TypeDescriptionConfidence
RegionIsrael
Verified

Extracted IOCs

  • moses-staff[.]se
  • 1094aa25e2d637e7f5795edd6c0f60e4
  • 2372c7639e70820f253a098dfcaf5060
  • 3649c106c6edd7ef47acd46586c74d8e
  • 3dde69212234c98b503081d64b9beb52
  • 3dfb7626dbe46136bc19404b63c6d1dc
  • 5ffc255557796512798617ae61c4274d
  • 680ce7d56fc427ee2fbedb5baea59d68
  • 7be30062c1a2c42a7061dfbfec364588
  • 93c19436e6e5207e2e2bed425107f080
  • a06c125e6da566be67aacf6c4e44005e
  • a44775e7568b790505bbcaadbd61c993
  • c1bc20a9bbebbbdd19869999b9cec03b
  • e776c4e24c00fa3eeba68cde38ae24f3
download

Tip: 14 related IOCs (0 IP, 1 domain, 0 URL, 0 email, 13 file hash) to this threat have been found.

Overlaps

Cobalt SaplingUnmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations

Source: Secureworks - January 2023

Detection (one case): moses-staff[.]se

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: MosesStaff Cyberattacks Against Israeli Organizations

MosesStaff, an Iranian-linked threat group, launched a series of targeted cyberattacks against Israeli organizations beginning in September 2021. The attackers broke into networks through vulnerabilities in internet-facing servers, then deployed custom malware to steal data, encrypt entire systems, and lock victims out of their own computers — all without demanding any ransom. The goal was purely to cause damage and publicly humiliate Israeli organizations for political reasons.

The attacks are attributed to MosesStaff, a threat group believed to be ideologically motivated and aligned with Iranian state interests. The group openly declared its purpose: to "fight against the resistance and expose the crimes of the Zionists in the occupied territories." Unlike financially motivated cybercriminals, MosesStaff has no interest in ransom payments — their sole objective is destruction and public exposure of their victims.

The attacks were driven entirely by political and ideological motives — not financial ones. MosesStaff's goal was to cause maximum damage to Israeli organizations by permanently encrypting their systems and publicly leaking their stolen data. No ransom was demanded, and no decryption key was offered to victims. The group intended the encryption to be irreversible, functioning more like a destructive wiper than traditional ransomware.

The campaign was narrowly targeted at Israeli organizations across multiple industries. Check Point Research documented several incidents beginning in September 2021, with the group remaining active through at least mid-November 2021. Each attack was tailored to its specific target — the malware was compiled with hardcoded credentials and network information unique to each victim, indicating careful pre-attack reconnaissance rather than opportunistic scanning.

All confirmed victims were Israeli organizations. Check Point notes that MosesStaff joined a broader wave of politically motivated attacks against Israel that included groups like Pay2Key and BlackShadow. While the source does not identify specific victim sectors, the group targeted organizations across various Israeli industries, with the common thread being their Israeli identity rather than any particular sector or size.

Attackers first exploited vulnerabilities in internet-facing servers — primarily Microsoft Exchange — to plant a web shell and gain persistent access. They then moved through the network using legitimate tools like PsExec and PowerShell with stolen administrator credentials. Once inside, they deployed two custom tools: PyDCrypt, a dropper built per-victim that spread the payload across the network, and DCSrv, which encrypted every drive on each machine and installed a custom bootloader that locked computers on reboot. Victims were left with systems they could not access and no option to pay for recovery.

Israeli organizations represent high-value targets for politically motivated Iranian-aligned actors. The attacks align with a broader pattern of Iran-linked groups using cyber operations as a tool of political pressure against Israel. MosesStaff specifically aims to embarrass and damage Israeli entities in the public eye, leaking their data while simultaneously crippling their operations — maximizing both reputational and operational harm.

The most important step is patching all internet-facing systems immediately — MosesStaff does not use zero-day exploits and relies entirely on known, patchable vulnerabilities for initial access. Organizations should also monitor IIS directories for unexpected web shell files, restrict and audit use of remote execution tools like PsExec, and alert on svchost.exe processes running from non-standard paths. Deploying endpoint detection tools that log full process command-line parameters is especially valuable: Check Point notes that EDR logs may contain the encryption keys needed to reverse the DCSrv encryption if an incident has already occurred.

About Affiliation
Moses Staff
Moses Staff is an Iranian MOIS-linked hacktivist group that emerged in September 2021, conducting destructive cyberattacks and data theft exclusively against Israeli organizations across government, military, finance, and IT sectors. The group uses wiper malware disguised as ransomware — including the PyDCrypt encryptor and DCSrv tool — combined with public data leaks to maximize political and psychological impact. Moses Staff is tracked as Cobalt Sapling by Secureworks and DEV-0500/Marigold Sandstorm by Microsoft. The Abraham's Ax persona represents a related operation targeting Saudi Arabian organizations.
View Moses Staff's Insights