Skip to content

Moses Staff

Moses Staff is an alleged Iranian threat actor, also tracked as DEV-0500, DEV-500, Marigold Sandstorm, MosesStaff, and Vengeful Kitten.

Profile source: Mallory opens in a new tab

Moses Staff

Family profile

Moses Staff is an alleged Iranian threat actor, also tracked as DEV-0500, DEV-500, Marigold Sandstorm, MosesStaff, and Vengeful Kitten. The content states the group was first identified on underground forums in September 2021 and primarily targets Israeli companies by stealing and publishing sensitive data, with additional targeting reported in Italy, India, Germany, Chile, Turkey, the UAE, and the United States. One cited assessment says the group’s main activity is to damage Israeli companies by stealing and publishing sensitive data. Another cited report states leaked internal operational records confirmed direct infrastructure and administrative overlap between Moses Staff and CyberAv3ngers, formally connecting previously separate Iranian cyber personas into a single coordinated effort directed by the Iranian state.

The group is associated with destructive and disruptive activity rather than financial gain. The content states Moses Staff typically does not pursue financial gain and usually provides no practical way for victims to pay a ransom and decrypt data. Reported tooling includes the legitimate commercial/open-source tool DiskCryptor, including signed drivers from DiskCryptor to evade detection; custom tools PyDCrypt, DCSrv, and StrifeWater; and obfuscated web shells. PyDCrypt is described as a Python program built with PyInstaller that spreads within a network and ensures execution of DCSrv. DCSrv masquerades as svchost.exe, blocks access to the computer, and encrypts volumes using DiskCryptor. StrifeWater is described as a stealthy RAT used early in attacks to cover traces, execute remote commands, and capture the screen.

Observed behaviors in the content include collecting the compromised network’s domain name and infected host information such as machine names and OS architecture. ATT&CK-style mappings in the content associate Moses Staff with T1190 Exploit Public-Facing Application for initial access, T1505.003 Web Shell and T1505.004 IIS Components for persistence, T1059 Command and Scripting Interpreter for execution, and T1608.001/T1608.002 Upload Malware/Upload Tool for resource development. The content also explicitly notes use of obfuscated web shells in operations.

Operational record

1
YARA rules
2
Leak sites
0 available

MITRE ATT&CK

Moses Staff in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1082 System Information Discovery T1059 Command and Scripting Interpreter T1190 Exploit Public-Facing Application T1005 Data from Local System T1486 Data Encrypted for Impact T1588.002 Tool T1027 Obfuscated Files or Information T1059.006 Python T1570 Lateral Tool Transfer T1219 Remote Access Tools T1490 Inhibit System Recovery T1113 Screen Capture T1041 Exfiltration Over C2 Channel T1537 Transfer Data to Cloud Account T1036 Masquerading T1553.002 Code Signing T1608.002 Upload Tool T1505.003 Web Shell T1608.001 Upload Malware T1608 Stage Capabilities T1021.002 SMB/Windows Admin Shares T1505.004 IIS Components T1187 Forced Authentication T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay T1016 System Network Configuration Discovery T1562.004 Disable or Modify System Firewall T1087 Account Discovery T1105 Ingress Tool Transfer T1071.001 Web Protocols T1027.013 Encrypted/Encoded File T1087.001 Local Account T1595 Active Scanning T1587.001 Malware T1018 Remote System Discovery T1133 External Remote Services T1087.002 Domain Account T1069.002 Domain Groups T1046 Network Service Discovery T1069.001 Local Groups T1482 Domain Trust Discovery T1573.002 Asymmetric Cryptography T1055 Process Injection T1559 Inter-Process Communication T1021.003 Distributed Component Object Model T1047 Windows Management Instrumentation T1543.003 Windows Service T1021.001 Remote Desktop Protocol T1059.001 PowerShell T1204 User Execution T1505 Server Software Component T1571 Non-Standard Port T1590.001 Domain Properties T1590.005 IP Addresses T1203 Exploitation for Client Execution T1210 Exploitation of Remote Services T1656 Impersonation T1686.003 Disable or Modify System Firewall: Windows Host Firewall

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.