Threats Feed|Moses Staff|Last Updated 28/01/2026|AuthorCertfa Radar|Publish Date01/02/2022

StrifeWater: Unmasking the New RAT Deployed by Iranian APT Moses Staff

  • Actor Motivations: Espionage,Sabotage
  • Attack Vectors: Ransomware,RAT
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Iranian APT group Moses Staff deployed a new, previously undocumented Remote Access Trojan (RAT) called StrifeWater for its cyber-espionage and disruption operations. The StrifeWater RAT has been used in initial attack stages, demonstrating various capabilities like listing system files, executing system commands, creating persistence, and downloading updates. Post-infection, it's replaced with ransomware not for financial gain but to disrupt operations and inflict system damage. Victims of these attacks span globally across countries like Israel, Italy, India, Germany, Chile, Turkey, UAE, and the US.

Detected Targets

TypeDescriptionConfidence
SectorFinancial
Verified
SectorManufacturing
Verified
SectorEnergy
Verified
SectorPolitical
Verified
SectorTourism
Verified
RegionChile
Verified
RegionGermany
Verified
RegionIndia
Verified
RegionIsrael
Verified
RegionItaly
Verified
RegionTurkey
Verified
RegionUnited Arab Emirates
Verified
RegionUnited States
Verified

Extracted IOCs

  • techzenspace[.]com
  • 87[.]120.8.210
  • 87[.]120.8.210:80/rvp/index8[.]php
download

Tip: 3 related IOCs (1 IP, 1 domain, 1 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

Moses StaffIsraeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group

Source: Fortinet - February 2022

Detection (two cases): 87[.]120.8.210, techzenspace[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

About Affiliation
Moses Staff
Moses Staff is an Iranian MOIS-linked hacktivist group that emerged in September 2021, conducting destructive cyberattacks and data theft exclusively against Israeli organizations across government, military, finance, and IT sectors. The group uses wiper malware disguised as ransomware — including the PyDCrypt encryptor and DCSrv tool — combined with public data leaks to maximize political and psychological impact. Moses Staff is tracked as Cobalt Sapling by Secureworks and DEV-0500/Marigold Sandstorm by Microsoft. The Abraham's Ax persona represents a related operation targeting Saudi Arabian organizations.
View Moses Staff's Insights