Moses Staff is an Iran-linked threat actor best known for disruptive intrusions against Israeli organizations beginning in 2021. The group has also been tracked as DEV-0500, DEV-500, Marigold Sandstorm, MosesStaff, and Vengeful Kitten. Reporting has tied the operation to Iranian state-directed activity, and later overlap findings connected Moses Staff infrastructure and administration with other Iranian cyber personas. Moses Staff is notable for combining data theft, destructive or pseudo-ransomware behavior, and public leaking of stolen information. Unlike conventional financially motivated ransomware groups, it has been characterized by attacks intended to damage victims and publicize stolen data rather than reliably collect ransom payments. Victimology has centered heavily on Israel-based organizations, with additional targeting reported in other countries. Operationally, Moses Staff has exploited public-facing applications for initial access and used web shells, including IIS-related persistence mechanisms. The group has conducted host and network discovery, collecting details such as machine names, operating system architecture, domain information, and other environment data from compromised systems. It has used custom tooling including StrifeWater, a remote access trojan associated with early-stage access and remote command execution, alongside other malware used to support exfiltration and disruptive actions. A hallmark of Moses Staff tradecraft is abuse of the legitimate DiskCryptor utility and its signed drivers to encrypt systems or volumes while blending with legitimate software. The group has also used obfuscated web shells and other defense-evasion measures. Its activity profile aligns with espionage-enabled disruption and destructive operations directed primarily at Israeli targets, with data theft and publication serving coercive and psychological effects rather than straightforward monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
3 more CVEs tied to this actor tracked in Mallory.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in the detection metadata actor list.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with the detection for Metasploit-based Atlassian Confluence exploitation activity.
Listed as a threat actor associated with web shell persistence activity in the context of this VMware Workspace ONE web shell detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.