Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors mosesstaff

Also known as: Moses Staff, Marigold Sandstorm, DEV-0500, VENGEFUL KITTEN, tracked as, the Staff of Moses, the Arm of Yahweh, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

Moses Staff, first observed in September 2021, is a moderately sophisticated Iranian threat actor that blends criminal motives with political objectives. The group exploits the ProxyShell family of CVEs (CVE‑2021‑31207, CVE‑2021‑34473, CVE‑2021‑34523) against Microsoft Exchange to install custom backdoors and web shells such as IISpool.aspx, achieving persistence and enabling rapid network traversal. Once inside, Moses Staff deploys a set of automation tools—including Vatet Loader, Metasploit, Cobalt Strike—and its own StrifeWater RAT and PyDCrypt payload to gather system information, harvest credentials, and exfiltrate data. Rather than demanding a ransom, the actors encrypt victim files but publicly leak the stolen evidence via social media (Twitter, Telegram) to damage reputations. The group has demonstrated cross‑border reach, attacking government agencies, financial services, healthcare organizations, telecommunications companies, and other critical infrastructures in countries such as Israel, Italy, India, Germany, and the United States. The lack of direct ransom calls suggests a focus on political disruption and data monetization through publication rather than financial extortion. Operationally, Moses Staff has executed campaigns at moderate tempo, employing web‑shell persistence, firewall tampering scripts, and system discovery techniques to expand reach within compromised environments. Their attacks typically conclude with exfiltration over standard and non‑standard channels followed by public disclosure of the stolen data.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Manufacturing
Education
Energy
Media
Non profit
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Aerospace
Transportation
Retail
Information technology
Think tank
Mining
Chemical
Gaming
Utilities
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction

Targeted Countries / Regions

US
CN
AE
RU
IL
DE
IN
IR
TR
VN
JP
IT
GB
AU
SA
PK
TW
UA
SG
KR
BY
MX
ES
PL
CA
RO
FR
NG
KP
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 7 hours ago

Executive Summary

Moses Staff is an Iranian-origin threat group that operated in late 2021, primarily targeting Israeli and other international entities across a wide range of sectors. The actor leveraged ProxyShell Exchange vulnerabilities to gain initial access, deployed custom RATs and web shells for lateral movement, and opted not to demand ransom— instead encrypting data and publicly releasing stolen information to tarnish victims' reputations.

Goals & Targeting

The group’s strategic objective appears to be financial gain through data theft while simultaneously executing politically motivated campaigns aimed at Israeli targets. By encrypting files without demanding payment, they create operational disruption; leaking sensitive information publicly serves both reputational damage and potential monetization via secondary markets or influence operations. Target selection spans a broad spectrum of critical sectors, underscoring an opportunistic approach to maximize impact across multiple industries.

Enhanced Description

Key Capabilities

  • Exploitation of ProxyShell CVEs (CVE‑2021‑31207, CVE‑2021‑34473, CVE‑2021‑34523) for initial access
  • Use of third‑party exploitation frameworks such as Vatet Loader, Metasploit, and Cobalt Strike
  • Deployment of custom backdoors and web shells (e.g., IISpool.aspx) for persistence and network traversal
  • Execution of batch scripts that disable Windows Firewall on remote hosts
  • Collection of administrator usernames from compromised systems
  • Encrypting victim networks without demanding ransom and leaking stolen data publicly via social media

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1053.005
T1113
T1033
T1114
T1573.001
T1082
T1005
T1140
T1190
T1055
T1021
T1505.003
T1003.001
T1016
T1087
T1083
T1480
T1041
T1134.004
T1027
T1553
T1588
T1059.003
T1505
T1071.001
T1105
T1587
T1686
T1569.002
T1008

Software / Tooling

Vatet Loader
Metasploit
Cobalt Strike
StrifeWater RAT
DCSrv
PyDCrypt

Campaigns & Victims

Moses Staff operated primarily during late 2021, with evidence of 16 victims spanning government ministries, financial institutions, and critical infrastructure across 11 nationalities. The attacks exhibit a consistent pattern: compromise Microsoft Exchange via ProxyShell, drop web shells for persistence, use RATs to harvest credentials, exfiltrate data through standard channels (S3, FTP) or custom C2 communications, then publicly post the stolen content on Twitter or Telegram. The actor’s tempo is moderate—enabling quick escalation in newly compromised networks but rarely engaging in prolonged campaigns.

IOC Patterns

  • domain
  • file
  • ip-v4
  • hash-sha256
  • url
  • hash-sha1

Recommended Actions

  • Patch Microsoft Exchange servers to mitigate ProxyShell vulnerabilities (CVE‑2021‑31207, CVE‑2021‑34473, CVE‑2021‑34523).
  • Block known malicious IP addresses and monitor DNS traffic for indicators of compromise such as suspicious subdomains.
  • Deploy anti‑malware signatures and behavior detection for custom RATs (StrifeWater) and web shells (IISpool.aspx).
  • Conduct regular endpoint scans for unauthorized webshell files and suspicious driver DLLs (e.g., lic.dll, inj.dll, drvguard.exe).
  • Enforce group policy to prevent manipulation of Windows Firewall via batch scripts.
  • Implement network segmentation to limit lateral movement and isolate Exchange servers.
  • Educate users about phishing attempts that may introduce initial malware into the environment.

Suggested Tags

Iranian
State-sponsored?
Politically motivated
APT group
Ransomware (no ransom demand)
ProxyShell exploitation
WebShell deployment
Custom RAT
Target sectors: government, finance, travel, energy, manufacturing, utility
Target countries: Israel, Italy, India, Germany, United States

Confidence Assessment

The available data derives from multiple independent security research teams and corroborated by MITRE ATT&CK references, providing moderate to high confidence in the identified tactics, techniques, and initial‑access vectors. However, gaps remain regarding definitive state sponsorship versus a purely criminal enterprise, the extent of campaigns beyond 2021, and whether newer variants employ additional capabilities or tools not captured here.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 2 SHA-256 Hash 3 SHA-1 Hash 3 Domain 8 Filename 4

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: T1190
  3. www.fortinet.com — Cited by web research for: T1505.003
  4. www.sentinelone.com — Cited by web research for: Singularity
  5. www.cybereason.com — Cited by web research for: PowerLess
  6. apt.etda.or.th — Cited by web research for: Government
  7. https://www.cybereason.com/blog/research/strifewater-rat-iranian-apt-moses-staff-adds-new-trojan-to-ransomware-op — Cited by AI analysis.
  8. https://www.secureworks.com/blog/abrahams-ax-likely-linked-to-moses-staff — Cited by AI analysis.

Intel Summary

30

Techniques

53

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Iranian
State-sponsored?
Politically motivated
APT group
Ransomware (no ransom demand)
ProxyShell exploitation
WebShell deployment
Custom RAT
Target sectors: government, finance, travel, energy, manufacturing, utility
Target countries: Israel, Italy, India, Germany, United States

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
I
Confidence
80%
First Seen
Dec 18, 2021
Last Seen
Dec 18, 2021
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.