Unmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations
- Actor Motivations: Exfiltration,Sabotage
- Attack Vectors: Backdoor,RAT,Wiper
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Secureworks Counter Threat Unit links two separate hacktivist personas — Moses Staff and Abraham's Ax — to a single Iranian threat group tracked as COBALT SAPLING. Moses Staff emerged in September 2021, targeting Israeli companies and individuals tied to Israel's signals intelligence Unit 8200 through data theft, leaks, and destructive encryption using the PyDCrypt loader and DCSrv wiper. Abraham's Ax surfaced in November 2022, pivoting to attack Saudi Arabian government ministries — likely in response to reported Israeli-Saudi normalization efforts that Iran perceived as a regional threat. Secureworks identifies the link through overlapping infrastructure: both groups' leak sites were hosted in near-adjacent IP addresses within the same subnet at early points in their operation, a pattern assessed as highly unlikely to be coincidental. Additional shared indicators include nearly identical logo style, multilingual WordPress-based leak sites both registered through the same Swedish registrar, reused video production elements, and the same ASPX web shells used in intrusions attributed to Moses Staff. The StrifeWater RAT and DriveGuard tool have been linked to COBALT SAPLING through technical overlaps across intrusions. Malware artifacts suggest the group has been active since at least November 2020, predating the Moses Staff persona's public debut by nearly a year.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Israeli Intelligence Corps As an Israeli signals intelligence unit, Unit 8200 may have been targeted by Moses Staff by stealing data and leaking personal information. The Israeli Intelligence Corps, abbreviated to Haman is an Israel Defense Forces corps which falls under the jurisdiction of IDF Directorate of Military Intelligence and is responsible for collecting, disseminating, and publishing intelligence information for the General Staff and the political branch. Israeli Intelligence Corps has been targeted by Cobalt Sapling as the main target. | Verified |
| Sector | Government Agencies and Services | Verified |
| Region | Israel | Verified |
| Region | Saudi Arabia | Verified |
Extracted IOCs
- abrahams-ax[.]nu
- abrahams-ax[.]se
- moses-staff[.]se
- 63c4c31965ed08a3207d44e885ebd5e4
- a70d6bbf2acb62e257c98cb0450f4fec
- aba68c4b4482e475e2d4b9bf54761b95
- 5cacfad2bb7979d7e823a92fb936c5929081e691
- 76a35d4087a766e2a5a06da7e25ef76a8314ec84
- 7a5d75db6106d530d5fdd04332c68cd7ccec287f
- 1d84159252ed3fc814074312b85f62993e0476b27c21eec6cc1cc5c5818467e7
- cafa8038ea7e46860c805da5c8c1aa38da070fa7d540f4b41d5e7391aa9a8079
- ff15558085d30f38bc6fd915ab3386b59ee5bb655cbccbeb75d021fdd1fde3ac
- 95[.]169.196.52
- 95[.]169.196.55
Tip: 14 related IOCs (2 IP, 3 domain, 0 URL, 0 email, 9 file hash) to this threat have been found.
Overlaps
Source: Fortinet - February 2022
Detection (two cases): cafa8038ea7e46860c805da5c8c1aa38da070fa7d540f4b41d5e7391aa9a8079, ff15558085d30f38bc6fd915ab3386b59ee5bb655cbccbeb75d021fdd1fde3ac
Source: Checkpoint - November 2021
Detection (one case): moses-staff[.]se
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: COBALT SAPLING — Moses Staff and Abraham's Ax Operations
Secureworks researchers uncovered that two separate hacktivist groups — Moses Staff and Abraham's Ax — are almost certainly run by the same Iranian threat group, known as COBALT SAPLING. Moses Staff has been attacking Israeli organizations since late 2020, stealing and leaking data while encrypting victims' systems. Abraham's Ax emerged in November 2022 with a similar playbook, but aimed at Saudi Arabian government ministries instead. The report documents the infrastructure, tooling, and visual similarities that tie the two personas together.
Both personas are attributed to COBALT SAPLING, an Iranian state-aligned threat group. Moses Staff presents itself as a pro-Palestinian hacktivist collective targeting Israel. Abraham's Ax claims to act on behalf of Hezbollah's Ummah and targets Saudi Arabia — though Secureworks finds no actual evidence of a Hezbollah connection. The Iranian government connection is inferred from the group's geopolitical targeting, tooling, and operational patterns rather than any direct claim of state sponsorship.
The goals are political disruption and intimidation — not financial gain. Moses Staff aims to damage Israel's image and expose what it calls "Zionist crimes" by stealing and leaking sensitive data, then destroying victim systems with no ransom option. Abraham's Ax targets Saudi Arabia, likely to undermine Saudi-Israeli normalization efforts that Iran sees as a threat. Both personas combine data leaks with propaganda videos to maximize public impact.
Moses Staff has posted 16 claimed operations against Israeli targets, including stolen datasets from Israeli companies and personal data on individuals affiliated with Unit 8200, Israel's signals intelligence unit. Abraham's Ax has targeted at least two Saudi Arabian government ministries, publishing alleged stolen documents and purported recordings of ministerial phone calls. Operations have been ongoing since at least November 2020, with the group active across two distinct geographic theaters.
Moses Staff focuses on Israeli private sector companies and individuals connected to Israel's military intelligence apparatus, particularly Unit 8200. Abraham's Ax targets Saudi Arabian government ministries. The sector targeting reflects the group's political objectives rather than any particular industry interest — the common thread is geopolitical significance to Iran's regional agenda.
COBALT SAPLING gains initial access via vulnerabilities in internet-facing servers, deploying custom ASPX web shells to maintain persistent access. From there, the StrifeWater RAT provides remote control, while the DriveGuard tool ensures it stays running. For destructive operations, PyDCrypt — compiled per victim with hardcoded network credentials — spreads across the network and deploys DCSrv, which encrypts all drive volumes using the DiskCryptor library and locks systems with a custom bootloader. Stolen data is published on leak sites and propaganda videos are released to amplify the psychological impact.
Israeli organizations are targeted because of Iran's longstanding geopolitical opposition to Israel. Saudi Arabian organizations became targets in late 2022 following reports of Israeli-Saudi normalization talks on air defense cooperation — a development Iran views as a direct threat to its regional influence. Both target sets represent Iran's broader effort to destabilize relationships and partnerships it considers hostile to its interests.
Organizations should block the known COBALT SAPLING domains and IPs listed in Secureworks' indicators table. Security teams should scan IIS directories for unexpected ASPX web shells and use the published StrifeWater RAT hashes to hunt for existing infections. Internet-facing servers — particularly Microsoft Exchange — should be fully patched, as the group relies on known vulnerabilities for initial access. Given that both personas remain active and share the same toolset, defenders in Israel and Saudi Arabia should treat COBALT SAPLING as an ongoing threat.