PyDCrypt is a custom Windows malware component associated with Moses Staff, an Iran-linked cluster also tracked under the broader Cobalt Sapling umbrella. It is described as a Python program packaged with PyInstaller and used in intrusions against victim organizations, particularly in operations involving data theft, network propagation, and preparation for disruptive follow-on activity. PyDCrypt has been observed alongside other Moses Staff tooling, notably DCSrv and StrifeWater, in campaigns targeting Israeli organizations and other victims across multiple countries.
Functionally, PyDCrypt appears to serve as a lateral movement and execution-enablement component rather than the final disruptive payload itself. It has been used to infect additional computers on a victim network and to ensure that the main payload, DCSrv, is executed properly. Observed behavior includes dropping DCSrv to disk while masquerading it as a legitimate Windows process, executing commands through PowerShell and WMIC, modifying firewall rules on remote machines to permit SMB, NetBIOS, and RPC connectivity, and probing compromised hosts with whoami to collect the current username. These behaviors indicate a role in post-compromise reconnaissance, remote execution, internal spread, and operational staging.
PyDCrypt has been linked to incidents in which files were exfiltrated from targeted organizations using custom Moses Staff malware. In the broader Moses Staff intrusion chain, PyDCrypt supports access expansion and payload deployment, while DCSrv has been associated with host lockout and DiskCryptor-based volume encryption. This places PyDCrypt within a toolset used for espionage, data theft, and disruptive operations against enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although the threat intelligence research community has identified custom offensive tooling observed in Moses Staff attacks, such as StrifeWater, PyDCrypt and DCSrv, we do not exclude the possibility of Moses Staff and Abraham’s Ax sharing tooling and operational practices making accurate clustering challenging at this time.
the files seem to have been exfiltrated through the use of malware from computers belonging to the targeted organization, and this behavior has been carried out by this threat actor using custom tools, such as PyDCrypt, DCSrv, and StrifeWater. PyDCrypt is a program written in Python and built with PyInstaller that is used to infect other computers on the network and ensure that the main payload DCSrv is executed properly.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples include 'Mosquito’s installer is obfuscated with a custom crypter,' 'PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag,' and 'Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom offensive tooling observed in Moses Staff attacks, likely used in disruptive and espionage-linked operations.
Ransomware that probes victim machines with whoami and collects the username.
Custom malware built by Moses Staff for targeting victims' machines.
A Python/PyInstaller-based malware tool used to infect other computers on the network and ensure execution of the main payload DCSrv.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.