mosesstaff
Group profile
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies by leaking sensitive, stolen data.
MITRE ATT&CK TTPs
Initial Access
T1190Exploit Public-Facing Application
[Moses Staff](https://attack.mitre.org/groups/G1009) has exploited known vulnerabilities in public-facing infrastructure such as Microsoft Exchange Servers.(Citation: Checkpoint MosesStaff Nov 2021)
Persistence
T1505.003Server Software Component: Web Shell
[Moses Staff](https://attack.mitre.org/groups/G1009) has dropped a web shell onto a compromised system.(Citation: Checkpoint MosesStaff Nov 2021)
Stealth
T1027.013Obfuscated Files or Information: Encrypted/Encoded File
[Moses Staff](https://attack.mitre.org/groups/G1009) has used obfuscated web shells in their operations.(Citation: Checkpoint MosesStaff Nov 2021)
Discovery
T1016System Network Configuration Discovery
[Moses Staff](https://attack.mitre.org/groups/G1009) has collected the domain name of a compromised network.(Citation: Checkpoint MosesStaff Nov 2021)
T1082System Information Discovery
[Moses Staff](https://attack.mitre.org/groups/G1009) collected information about the infected host, including the machine names and OS architecture.(Citation: Checkpoint MosesStaff Nov 2021)
T1087.001Account Discovery: Local Account
[Moses Staff](https://attack.mitre.org/groups/G1009) has collected the administrator username from a compromised host.(Citation: Checkpoint MosesStaff Nov 2021)
Lateral Movement
T1021.002Remote Services: SMB/Windows Admin Shares
[Moses Staff](https://attack.mitre.org/groups/G1009) has used batch scripts that can enable SMB on a compromised host.(Citation: Checkpoint MosesStaff Nov 2021)
Command and Control
T1105Ingress Tool Transfer
[Moses Staff](https://attack.mitre.org/groups/G1009) has downloaded and installed web shells to following path <code>C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx</code>.(Citation: Checkpoint MosesStaff Nov 2021)
Resource Development
T1587.001Develop Capabilities: Malware
[Moses Staff](https://attack.mitre.org/groups/G1009) has built malware, such as [DCSrv](https://attack.mitre.org/software/S1033) and [PyDCrypt](https://attack.mitre.org/software/S1032), for targeting victims' machines.(Citation: Checkpoint MosesStaff Nov 2021)
T1588.002Obtain Capabilities: Tool
[Moses Staff](https://attack.mitre.org/groups/G1009) has used the commercial tool DiskCryptor.(Citation: Checkpoint MosesStaff Nov 2021)
Defense Impairment
T1553.002Subvert Trust Controls: Code Signing
[Moses Staff](https://attack.mitre.org/groups/G1009) has used signed drivers from an open source tool called DiskCryptor to evade detection.(Citation: Checkpoint MosesStaff Nov 2021)
T1686.003Disable or Modify System Firewall: Windows Host Firewall
[Moses Staff](https://attack.mitre.org/groups/G1009) has used batch scripts that can disable the Windows firewall on specific remote machines.(Citation: Checkpoint MosesStaff Nov 2021)
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2021-12-18 | E Electron Csillag | Not Found | |
| 2021-12-18 | M Meshulam | Not Found | |
| 2021-12-18 | D DOSIK Technology | Technology | |
| 2021-12-18 | E Epsilor Company | Technology | |
| 2021-12-18 | F First part of Israel Post data leaked | Government & Defense | |
| 2021-12-18 | I Israel MOD and Benny Gantz | Government & Defense | |
| 2021-12-18 | F First part of Epsilor data leaked | Technology | |
| 2021-12-18 | E Ehud Leviathan Engineering | Manufacturing | |
| 2021-12-18 | D David Engineers | Manufacturing | |
| 2021-12-18 | H H.G.M Engineering | Manufacturing | |
| 2021-12-18 | A AHEC Tax Solutions | Financial Services | |
| 2021-12-18 | V V-ON | Not Found | |
| 2021-12-18 | M MATITIAHU BRUCHIM Law office | Professional Services | |
| 2021-12-18 | U Unit 8200 | Government & Defense | |
| 2021-12-18 | 3 3D imagery of israel | Technology | |
| 2021-12-18 | T This is just the beginning | Not Found |

