Moses Staff is an Iran-aligned group that emerged in 2021 conducting politically motivated, destructive hack-and-leak operations against Israeli organizations, encrypting systems with no recovery option and leaking stolen data — an anti-Israel disruption mission masked behind a hacktivist persona. A Saudi-focused offshoot operated as Abraham's Ax.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Moses Staff surfaced in September-November 2021 and was detailed by Check Point Research and Cybereason. It is assessed with medium confidence as an Iran-aligned state-directed operation using a hacktivist front for deniability and psychological effect, rather than a genuine grassroots collective; it has no MITRE Group ID. Microsoft tracks the cluster as DEV-0500 / Marigold Sandstorm and links it to the related Abraham's Ax persona.
The group's tradecraft centers on destruction, not extortion: after gaining access (often via exploitation of internet-facing servers such as Microsoft Exchange ProxyShell), it deploys the PyDCrypt loader and DCSrv wiper/encryptor built on the open-source DiskCryptor, locking systems with no intent to provide decryption. Cybereason documented the addition of the StrifeWater RAT for reconnaissance and to mask the destructive phase. Stolen data and screenshots are published via Telegram and a leak site for maximum political impact.
MENA targeting is the group's entire mission. Moses Staff concentrated on Israeli organizations across manufacturing, engineering, finance, utilities, and government; the Abraham's Ax offshoot extended the model to Saudi Arabian government ministries, framing operations around anti-Israel and anti-Saudi-normalization themes.
Distinct Moses Staff / Abraham's Ax activity is assessed as largely dormant after 2022-2023, with the broader Iranian destructive-persona mission continuing through actors like Void Manticore/Handala and Agrius. It is included as a net-new destructive-cluster historical entry, flagged medium confidence and G-ID-less.