Moses Staff has collected the domain name of a compromised network.3
group
Moses Staff G1009
- Created
- 11 August 2022
- Last modified
- 31 July 2026
- Aliases
- Moses Staff · DEV-0500 · Marigold Sandstorm
Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly stated their motivation in attacking Israeli companies is to cause damage by leaking stolen sensitive data and encrypting the victim's networks without a ransom demand.[1]
Security researchers assess Moses Staff is politically motivated, and has targeted government, finance, travel, energy, manufacturing, and utility companies outside of Israel as well, including those in Italy, India, Germany, Chile, Turkey, the UAE, and the US.[2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1009
Moses Staff has used batch scripts that can enable SMB on a compromised host.4
Moses Staff has used obfuscated web shells in their operations.5
Moses Staff collected information about the infected host, including the machine names and OS architecture.6
Moses Staff has collected the administrator username from a compromised host.7
Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.8
Standing G1009
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
39th percentile · 61% of 176 ATT&CK groups have more Enterprise techniques.
48th percentile · 52% of 176 ATT&CK groups have more tactics spanned.
55th percentile · 55% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
67th percentile · 67% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1009
616 distinct rules cover the 12 techniques recorded for this group. The 653 technique-to-rule mappings resolve to 616 distinct rules, because one rule can cover several techniques. 405 Sigma · 211 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org