PyDCrypt

MITRE ATT&CK: S1032 View on attack.mitre.org

Aliases: PyDCrypt

First seen
2021-09-01 00:00:00
Malware type
dropper, trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:00:27

Targeted industries: government-and-public-sector education-and-nonprofits

Targeted regions: country_code:ir country_code:il

Context

PyDCrypt is malware written in Python designed to deliver DCSrv. It has been used by Moses Staff since at least September 2021, with each sample tailored for its intended victim organization.

Detection coverage

  • 341 Sigma rules

Malware & tools used

  • Python (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • File Deletion (attack-pattern)

Used by threat actors

Reports & references

  • research.checkpoint.com — Mosesstaff Targeting Israeli Companies (report)
  • MITRE ATT&CK — S1032 (report)

External references