MosesStaff
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies by leaking sensitive, stolen data.
MosesStaff is an Iranian threat actor known for data theft and leak operations targeting Israeli companies.
MosesStaff is an Iranian threat actor motivated to harm Israeli companies by stealing and leaking sensitive data. They gain initial access by exploiting public-facing applications, maintain persistence via Web Shells, and use custom malware like PyDCrypt and StrifeWater along with tools like PsExec. Their TTPs include network and local account discovery, lateral movement via SMB, defense impairment by disabling the Windows host firewall, and code signing. Defenders should prioritize patching internet-facing systems, monitoring for Web Shell activity, unusual PsExec usage, and data exfiltration indicators.
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies by leaking sensitive, stolen data.
Monitor organizational external network traffic to detect malware and tool development and acquisition.
Monitor perimeter network traffic and server logs to detect exploit attempts against public-facing applications.
Monitor web server logs and file system changes for web shell detection.
Monitor file system access and file contents to detect suspicious encrypted or encoded files.
Monitor system and user activity to detect system network configuration and local account discovery.
Monitor network traffic and SMB traffic to detect lateral movement via SMB/Windows Admin Shares.
Monitor network traffic and file system access to detect Ingress Tool Transfer.
Monitor system and user activity, as well as code signing certificates, to detect code signing and Windows Host Firewall changes.
MosesStaff's main goal is to harm Israeli companies by stealing and leaking their sensitive data.
After gaining initial access by exploiting vulnerabilities in public-facing applications, MosesStaff maintains persistence on the targeted network by deploying Web Shells.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.