Skip to main content

Politically Motivated Moses Staff Hackers Group Targeting Israeli Organizations for Cyber Espionage.



The politically motivated Moses Staff hacker group has been observed using a custom multi-component toolset with the goal of carrying out espionage against its targets as part of a new campaign that exclusively singles out Israeli organizations.


First publicly documented in late 2021, Moses Staff is believed to be sponsored by the Iranian government, with attacks reported against entities in Israel, Italy, India, Germany, Chile, Turkey, the U.A.E., and the U.S.


Earlier this month, the hacker collective was observed incorporating a previously undocumented remote access trojan (RAT) called "StrifeWater" that masquerades as the Windows Calculator app to evade detection.



"Close examination reveals that the group has been active for over a year, much earlier than the group's first official public exposure, managing to stay under the radar with an extremely low detection rate," findings from FortiGuard Labs show.


The latest threat activity involves an attack path that leverages the ProxyShell vulnerability in Microsoft Exchange servers as an initial infection vector to deploy two web shells, followed by exfiltrating Outlook Data Files (.PST) from the compromised server.


Subsequent phases of the infection chain involve an attempt to steal credentials by dumping the memory contents of a critical Windows process called Local Security Authority Subsystem Service (Lsass.exe), before dropping and loading the "StrifeWater" backdoor (broker.exe).


The installation of the "Broker" implant, which is used to execute commands fetched from a remote server, download files, and exfiltrate data from target networks, is facilitated by a loader that masquerades as a "Hard Disk Drives Fast Stop Service" dubbed "DriveGuard" (drvguard.exe).


On top of that, the loader is also responsible for launching a watchdog mechanism ("lic.dll") that ensures its own service is never interrupted by restarting the DriveGuard every time it's stopped as well as ensuring that the loader is configured to run automatically on system startup.



The broker backdoor, for its part, is also equipped to delete itself from the disk using a CMD command, capture screenshots, and update the malware to replace the current module on the system with a file received from the server.


StrifeWater is also notable for its attempts to slip past defense gateways by posing as the Windows Calculator app (calc.exe), with FortiGuard Labs researchers discovering two older samples dating back to the end of December 2020, suggesting that the campaign has been operational for over a year.


The attribution to Moses Staff is based on similarities in the web shells used in previously disclosed attacks and its pattern of victimology.


"The group is highly motivated, capable, and set on damaging Israeli entities," the researchers said. "At this point, they continue to depend on 1-day exploits for their initial intrusion phase. Although the attacks we identified were carried out for espionage purposes, this does not negate the possibility that the operators will later turn to destructive measures."



#THN


#osutayusuf

Comments

Popular posts from this blog

Arrested Arua City Officials Taken to Kampala this Night.

Wednesday 8-November-2023. 📸: The arrest of Arua City Physical Planner Mr Findru Moses on 6-Nov-2023 at around 2pm. 📸: Mr Jobile Cornelius the City Deputy town clerk who was arrested on 7-Nov-2023 at around 4pm. 📸: Mrs Lillian Aleni (in red cloth) and Mr Edoni Benard being handcuffed by police officer on 6-Nov-2023 at around 6pm. The bail that was to be issued last night 8pm 7-Nov-2023 to release the arrested City Deputy town clerk Mr Jobile Cornelius and CFO Mr Sam Adriko over mismanagement of government properties and monies was canceled, and by this time of the night 11pm, highly placed sources leaked that, all the arrested suspects (Mr Findru Moses the Arua City Physical Planner, Mr Jobile Cornelius the Deputy City clerk, Mr Adriko Sam the CFO, Mr Edoni Benard the PDM BOG Chairperson for Pangisa ward and Mrs Lillian Aleni the parish chief for Pangisa ward) are being transported by State House Anti-corruption Unit officers who will soon be reac

Wedded Ayivu West MP Lematia John Fights Over Another Woman.

  📸: Hon Lematia John. By URN. Police in Arua district are investigating a case of assault and threatening violence involving the Member of Parliament for Ayivu West Constituency John Lematia and James Ariko, a DSTV technician in Arua city. Drama ensued on Easter Sunday 31-3-2024 at Dream Land Hotel located at Kuluva trading center along Arua-Nebbi highway in Arua district when the legislator and the technician engaged in a fight reportedly over a woman identified as Faith Eyotaru 25, a relationship officer at Victoria University Kampala. The scuffle started after Ayivu West Mp John Lematia went to swim at Dreamland Hotel with Faith Eyotaru only to find Ariko, who had gone to the same hotel earlier. However, upon seeing the duo coming out of the vehicle, Ariko confronted Lematia with both men claiming to be having a relationship with the lady. It took the intervention of the staff at the hotel who intervened and separated the fight between the men. Josephine Angucia, the West Nile re

41-Years-Old Man Digs His Own Grave in Maracha District.

Story by Osuta Yusuf.  Maracha District.  📸: The grave been dug by Mr Opiga Michael, a victim of frustration. Photo taken by Osuta Yusuf , on Wednesday 11-September-2024. The residents of Ebapi village, Baria Parish in Nyadri Sub-county, Maracha east constituency, Maracha District are in shock after a 41 year old man started digging his own grave. The man, identified as Mr Opiga Michael, who seems to be frustrated over some challenges in life, started digging his own grave on Tuesday 10-September-2024 until he was stopped by the elders in Nyaria clan. 📸: Opiga Michael, the Victim of Frustration. Photo by Osuta Yusuf , Information is Power. While speaking to our reporter on Wednesday evening 11-September-2024, Mr Opiga Michael, said, his main plan  was to commit suicide after finishing digging the grave for burying himself, explained that, he feels frustrated, abandoned and hated by his own clan people, whom he accused of piling lies against him and some even a