Iran-linked hacktivist group known for destructive wiper attacks against Saudi government institutions.
Analyst brief
Abrahams_Ax is an Iranian-linked hacktivist persona associated with Moses Staff that appeared in November 2022. It primarily targets Saudi Arabian government institutions for geopolitical motives tied to Saudi-Israeli normalization. The group employs destructive wiper malware and data leak tactics, distinguishing itself from financially driven ransomware operations. Defenders should focus on network segmentation for critical assets, robust offline backups, and integrity monitoring for signs of wiper infections.
Abrahams_Ax
crime
Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily targeting Saudi Arabian government institutions for geopolitical reasons related to Saudi-Israeli normalization, using destructive wiper malware and data leak tactics rather than financial ransomware.
The group primarily uses destructive wiper malware, conducts cyber espionage operations, and employs data leak tactics. Notably, the group does not use ransomware.
What are the primary targets of Abrahams_Ax?+
Abrahams_Ax primarily targets Saudi Arabian government institutions for geopolitical reasons tied to Saudi-Israeli normalization.