PyDCrypt is a custom malware tool associated with Moses Staff and referenced in reporting on the Iran-linked proxy cluster Cobalt Sapling. It is described as a Python program built with PyInstaller that is used to infect other computers on a victim network and to ensure execution of the main payload, DCSrv. Observed behavior includes probing victim machines with whoami and collecting the username, attempting execution via PowerShell and WMIC, dropping DCSrv to disk under the filename svchost.exe, and modifying firewall rules on remote machines with netsh.exe to allow incoming SMB, NetBIOS, and RPC connections. Reporting also notes use of netsh in connection with RPC discovery on remote machines. PyDCrypt has been discussed alongside other Moses Staff tooling including DCSrv and StrifeWater, and has been linked to malware-enabled exfiltration activity against targeted organizations, including Israeli victims. High-confidence related context indicates DCSrv masquerades as svchost.exe and is used in Moses Staff operations involving disruptive encryption behavior via DiskCryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although the threat intelligence research community has identified custom offensive tooling observed in Moses Staff attacks, such as StrifeWater, PyDCrypt and DCSrv, we do not exclude the possibility of Moses Staff and Abraham’s Ax sharing tooling and operational practices making accurate clustering challenging at this time.
the files seem to have been exfiltrated through the use of malware from computers belonging to the targeted organization, and this behavior has been carried out by this threat actor using custom tools, such as PyDCrypt, DCSrv, and StrifeWater. PyDCrypt is a program written in Python and built with PyInstaller that is used to infect other computers on the network and ensure that the main payload DCSrv is executed properly.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples include 'Mosquito’s installer is obfuscated with a custom crypter,' 'PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag,' and 'Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom offensive tooling observed in Moses Staff attacks, likely used in disruptive and espionage-linked operations.
Custom malware built by Moses Staff for targeting victims' machines.
A Python/PyInstaller-based malware tool used to infect other computers on the network and ensure execution of the main payload DCSrv.
Ransomware that has attempted execution with PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.