Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli c...

Threat Actor Profile

MosesStaff

State-sponsored threat group originating from IR.

Real-Time Alerts

Actor Overview

Origin Country
IR

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on MosesStaff is published.

Actor Details

Primary Name
MosesStaff
Known Aliases
Moses Staff, Marigold Sandstorm, DEV-0500
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →