Moses Staff
Also reported as Marigold Sandstorm, DEV-0500, VENGEFUL KITTEN, MosesStaff, DEV-500 and 4 other names. Linked to Iran by four sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11634 KEV ransomware
- CVE-2019-5591 KEV ransomware
- CVE-2019-7481 KEV ransomware
- CVE-2020-12271 KEV ransomware
- CVE-2020-12812 KEV ransomware
Show all 51 CVEs Show fewer
- CVE-2020-1472 KEV ransomware
- CVE-2020-36198
- CVE-2020-5135 KEV ransomware
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8234
- CVE-2020-8260 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-20655
- CVE-2021-21974
- CVE-2021-2198
- CVE-2021-22893 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-2701
- CVE-2021-27065 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-28799 KEV ransomware
- CVE-2021-31166 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-36942 KEV ransomware
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-29489
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest
Show all 23 reports Show fewer
-
Abraham's Ax Likely Linked to Moses Staff
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Abraham's Ax Likely Linked to Moses Staff
-
Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Threat Report 2022
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Guard Your Drive from DriveGuard- Moses Staff Campaigns Against Israeli Organizations Span Several Months
-
PowerLess Trojan- Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PowerLess Trojan- Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage
-
StrifeWater RAT- Iranian APT Moses Staff Adds New Trojan to Ransomware Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor StrifeWater RAT- Iranian APT Moses Staff Adds New Trojan to Ransomware Operations
-
Uncovering MosesStaff techniques- Ideology over Money
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering MosesStaff techniques- Ideology over Money
Newest first. Details opens the report in Explore.