ATT&CKGroupsMoses Staff

Moses Staff

G1009

Threat group.View on attack.mitre.org

About this group

Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly stated their motivation in attacking Israeli companies is to cause damage by leaking stolen sensitive data and encrypting the victim's networks without a ransom demand.

Security researchers assess Moses Staff is politically motivated, and has targeted government, finance, travel, energy, manufacturing, and utility companies outside of Israel as well, including those in Italy, India, Germany, Chile, Turkey, the UAE, and the US.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

Moses Staff has collected the domain name of a compromised network.

T1021.002
SMB/Windows Admin Shares

Moses Staff has used batch scripts that can enable SMB on a compromised host.

T1027.013
Encrypted/Encoded File

Moses Staff has used obfuscated web shells in their operations.

T1082
System Information Discovery

Moses Staff collected information about the infected host, including the machine names and OS architecture.

T1087.001
Local Account

Moses Staff has collected the administrator username from a compromised host.

T1105
Ingress Tool Transfer

Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.

T1190
Exploit Public-Facing Application

Moses Staff has exploited known vulnerabilities in public-facing infrastructure such as Microsoft Exchange Servers.

T1505.003
Web Shell

Moses Staff has dropped a web shell onto a compromised system.

T1553.002
Code Signing

Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection.

T1587.001
Malware

Moses Staff has built malware, such as DCSrv and PyDCrypt, for targeting victims' machines.

T1588.002
Tool

Moses Staff has used the commercial tool DiskCryptor.

T1686.003
Windows Host Firewall

Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines.

Software4

Campaigns0

None recorded.

References2

  1. Checkpoint MosesStaff Nov 2021 Open source
    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.
  2. Cybereason StrifeWater Feb 2022 Open source
    Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.