Ransomware Group intelligence
Mosesstaff
InactiveTrack Mosesstaff with 16 published victims and 2 known leak locations in a single intelligence view.
Overview
Mosesstaff is tracked by Breach House as a ransomware group with 16 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Web location | Down checked 58m ago | moses-staff.se |
| Leak location 1 | Onion service | Down checked 58m ago | mosesstaffm7hptp.onion |
Top Activity Sectors (5)
Typical Attacks (12)
▼How Mosesstaff typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Moses Staff.
-
T1587.001 Malware Resource Development
What they do: Moses Staff has built malware, such as DCSrv and PyDCrypt, for targeting victims' machines.
What that means: Adversaries may develop malware and malware components that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Moses Staff has used the commercial tool DiskCryptor.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Moses Staff has exploited known vulnerabilities in public-facing infrastructure such as Microsoft Exchange Servers.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1505.003 Web Shell Persistence
What they do: Moses Staff has dropped a web shell onto a compromised system.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Moses Staff has used obfuscated web shells in their operations.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1553.002 Code Signing Defense Impairment
What they do: Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1686.003 Windows Host Firewall Defense Impairment
What they do: Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines.
What that means: Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage.
-
T1016 System Network Configuration Discovery Discovery
What they do: Moses Staff has collected the domain name of a compromised network.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1082 System Information Discovery Discovery
What they do: Moses Staff collected information about the infected host, including the machine names and OS architecture.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1087.001 Local Account Discovery
What they do: Moses Staff has collected the administrator username from a compromised host.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Moses Staff has used batch scripts that can enable SMB on a compromised host.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1105 Ingress Tool Transfer Command and Control
What they do: Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
Victims (16)
Search, filter and paginate the victim timeline for Mosesstaff. Showing 1–16 of 16.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Electron Csillag id2240 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Meshulam id2239 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DOSIK Technology id2238 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Epsilor Company id2237 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | First part of Israel Post data leaked id2236 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Israel MOD and Benny Gantz id2235 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | First part of Epsilor data leaked id2234 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ehud Leviathan Engineering id2233 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | David Engineers id2232 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | H.G.M Engineering id2231 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AHEC Tax Solutions id2230 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | V-ON id2229 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MATITIAHU BRUCHIM Law office id2228 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unit 8200 id2227 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 3D imagery of israel id2226 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | This is just the beginning id2225 View details | Other | — | ||
|
No additional victim description available. |
|||||