Also known as: Moses Staff, Marigold Sandstorm, DEV-0500, VENGEFUL KITTEN, tracked as, the Staff of Moses, the Arm of Yahweh, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations
Moses Staff, first observed in September 2021, is a moderately sophisticated Iranian threat actor that blends criminal motives with political objectives. The group exploits the ProxyShell family of CVEs (CVE‑2021‑31207, CVE‑2021‑34473, CVE‑2021‑34523) against Microsoft Exchange to install custom backdoors and web shells such as IISpool.aspx, achieving persistence and enabling rapid network traversal. Once inside, Moses Staff deploys a set of automation tools—including Vatet Loader, Metasploit, Cobalt Strike—and its own StrifeWater RAT and PyDCrypt payload to gather system information, harvest credentials, and exfiltrate data. Rather than demanding a ransom, the actors encrypt victim files but publicly leak the stolen evidence via social media (Twitter, Telegram) to damage reputations. The group has demonstrated cross‑border reach, attacking government agencies, financial services, healthcare organizations, telecommunications companies, and other critical infrastructures in countries such as Israel, Italy, India, Germany, and the United States. The lack of direct ransom calls suggests a focus on political disruption and data monetization through publication rather than financial extortion. Operationally, Moses Staff has executed campaigns at moderate tempo, employing web‑shell persistence, firewall tampering scripts, and system discovery techniques to expand reach within compromised environments. Their attacks typically conclude with exfiltration over standard and non‑standard channels followed by public disclosure of the stolen data.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Moses Staff is an Iranian-origin threat group that operated in late 2021, primarily targeting Israeli and other international entities across a wide range of sectors. The actor leveraged ProxyShell Exchange vulnerabilities to gain initial access, deployed custom RATs and web shells for lateral movement, and opted not to demand ransom— instead encrypting data and publicly releasing stolen information to tarnish victims' reputations.
Goals & Targeting
The group’s strategic objective appears to be financial gain through data theft while simultaneously executing politically motivated campaigns aimed at Israeli targets. By encrypting files without demanding payment, they create operational disruption; leaking sensitive information publicly serves both reputational damage and potential monetization via secondary markets or influence operations. Target selection spans a broad spectrum of critical sectors, underscoring an opportunistic approach to maximize impact across multiple industries.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Moses Staff operated primarily during late 2021, with evidence of 16 victims spanning government ministries, financial institutions, and critical infrastructure across 11 nationalities. The attacks exhibit a consistent pattern: compromise Microsoft Exchange via ProxyShell, drop web shells for persistence, use RATs to harvest credentials, exfiltrate data through standard channels (S3, FTP) or custom C2 communications, then publicly post the stolen content on Twitter or Telegram. The actor’s tempo is moderate—enabling quick escalation in newly compromised networks but rarely engaging in prolonged campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data derives from multiple independent security research teams and corroborated by MITRE ATT&CK references, providing moderate to high confidence in the identified tactics, techniques, and initial‑access vectors. However, gaps remain regarding definitive state sponsorship versus a purely criminal enterprise, the extent of campaigns beyond 2021, and whether newer variants employ additional capabilities or tools not captured here.
No campaigns linked yet.
No observed data linked yet.
30
Techniques
53
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics