PyDCrypt — Malware Profile
PyDCrypt is malware written in Python designed to deliver DCSrv. It has been used by Moses Staff since at least September 2021, with each sample tailored for its intended victim organization.
MITRE ATT&CK techniques (11)
- T1027.013 Encrypted/Encoded File
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.006 Python
- T1070.004 File Deletion
- T1140 Deobfuscate/Decode Files or Information
- T1686 Disable or Modify System Firewall
IntelFusions coverage
- MosesStaff Technical Analysis: PyDCrypt Loader and DCSrv Wiper Use DiskCryptor for Ideologically Motivated Destruction Without Ransom 2026-02-16
- Abraham's Ax Linked to Moses Staff: COBALT SAPLING Operates Dual Hacktivist Personas Targeting Israel and Saudi Arabia 2026-02-16