Secureworks Counter Threat Unit researchers published an analysis on Secureworks connecting the Abraham's Ax persona (emerged November 2022) to the Moses Staff hacktivist group (emerged September 2021), concluding both are operated by the Iranian COBALT SAPLING threat group. The analysis is based on shared iconography style, parallel site infrastructure hosted in near-contiguous IP space, identical domain registrar (EgenSajt.se), reused video stock elements, and operational continuity — with Moses Staff remaining active after Abraham's Ax appeared, indicating the new persona supplements rather than replaces the original.
Infrastructure and Visual Fingerprints Connecting Both Personas
Both groups operate WordPress-based leak sites offering multilingual content (Moses Staff: Hebrew/English; Abraham's Ax: Hebrew/Farsi/English) with Tor mirrors. Domain registration traces both to EgenSajt.se: moses-staff.se (registered 2021-09-09), abrahams-ax.nu (2022-10-14, three weeks before the group's public emergence), and abrahams-ax.se (2022-11-08). CTU's hosting analysis found that at early points in their lifecycles both sites were hosted in the same subnet in near-adjacent IP address space — assessed as highly unlikely to occur by coincidence. Video production reveals further continuity: Abraham's Ax reuses the same stock video elements (satellites, CCTV, 3D building models, fast document scrolling, multiple mobile phones suggesting intercepted calls) seen in Moses Staff videos, with additional visual embellishments and an incongruous background of scrolling text from a 2015 David Cameron UK factory visit news report.
Moses Staff: Israel-Focused Disruption with PyDCrypt, DCSrv, and StrifeWater RAT
Moses Staff presents as anti-Israeli and pro-Palestinian, targeting Israeli companies and publishing personal data on individuals affiliated with Israel's Unit 8200 signals intelligence directorate. The group's technical toolkit includes the PyDCrypt loader, the DCSrv cryptographic wiper (encrypts data using open-source DiskCryptor and installs a custom bootloader message in a ransomware-styled but non-extortion attack focused on disruption and intimidation), the StrifeWater RAT (also known as brokerhost.exe, linked via shared customized ASPX web shells across intrusions), and the DriveGuard auxiliary tool deployed alongside StrifeWater to monitor its execution. Malware artifacts indicate COBALT SAPLING has been active since at least November 2020 — a full year before the Moses Staff persona emerged publicly in September 2021.
Abraham's Ax: Saudi Arabia Focus Reflecting Iran's Regional Counter-Normalization Strategy
Rather than targeting Israel directly, Abraham's Ax claims to operate on behalf of the "Hezbollah Ummah" and attacks Saudi Arabian government ministries — publishing sample data allegedly from the Ministry of the Interior and purported intercepted phone conversations between Saudi officials. CTU notes no evidence of actual Hezbollah involvement. The targeting aligns with Iran's interest in disrupting Saudi-Israeli normalization efforts: reporting from June 2022 described secret talks on potential air defense collaboration that Iran perceived as a direct regional threat. CTU assesses COBALT SAPLING likely uses the same tools and techniques across both personas, though no distinct Abraham's Ax malware indicators had been identified at time of publication.