Threat actor · all actors
Moses StaffG1009 hacktivist
🇮🇷 IR
aka Moses Staff, DEV-0500, Marigold Sandstorm, MosesStaff, VENGEFUL KITTEN
Last updated: 2026-08-20
About this actor
[Moses Staff](https://attack.mitre.org/groups/G1009) is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. [Moses Staff](https://attack.mitre.org/groups/G1009) openly stated their motivation in attacking Israeli companies is to cause damage by leaking stolen sensitive data and encrypting the victim's networks without a ransom demand.(Citation: Checkpoint MosesStaff Nov 2021) Security researchers assess [Moses Staff](https://attack.mitre.org/groups/G1009) is politically motivated, and has targeted government, finance, travel, energy, manufacturing, and utility companies outside of Israel as well, including those in Italy, India, Germany, Chile, Turkey, the UAE, and the US.(Citation: Cybereason StrifeWater Feb 2022)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 20 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1016System Network Configuration Discovery ↗T1021Remote Services ↗T1021.002SMB/Windows Admin Shares ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1082System Information Discovery ↗T1087Account Discovery ↗T1087.001Local Account ↗T1105Ingress Tool Transfer ↗T1190Exploit Public-Facing Application ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1686Disable or Modify System Firewall ↗T1686.003Windows Host Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 11 / 20 | 55% |
SI-4 | 11 / 20 | 55% |
CM-7 | 9 / 20 | 45% |
AC-2 | 8 / 20 | 40% |
AC-3 | 8 / 20 | 40% |
CM-2 | 8 / 20 | 40% |
AC-6 | 7 / 20 | 35% |
AC-5 | 6 / 20 | 30% |
CM-5 | 6 / 20 | 30% |
IA-2 | 5 / 20 | 25% |
SI-3 | 5 / 20 | 25% |
SI-7 | 5 / 20 | 25% |
CA-7 | 4 / 20 | 20% |
AC-4 | 3 / 20 | 15% |
CM-8 | 3 / 20 | 15% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Play 0.25
- ShadowRay 0.24
- MirrorFace 0.23
- Cutting Edge 0.22
- BackdoorDiplomacy 0.21
Same nation-state
- HomeLand Justice 1.00
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- OilRig 1.00
Same category
- Al-Toufan 1.00
- AnonOps 1.00
- Anonymous Brasil 1.00
- Anonymous Collective 1.00
- Anonymous France 1.00