PyDCrypt
MITRE ATT&CK: S1032 View on attack.mitre.org
Aliases: PyDCrypt
- First seen
- 2021-09-01 00:00:00
- Malware type
- dropper, trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:00:27
Targeted industries: government-and-public-sector education-and-nonprofits
Targeted regions: country_code:ir country_code:il
Context
PyDCrypt is malware written in Python designed to deliver DCSrv. It has been used by Moses Staff since at least September 2021, with each sample tailored for its intended victim organization.
Detection coverage
- 341 Sigma rules
Malware & tools used
- Python (attack-pattern)
- Windows Command Shell (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- PowerShell (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- File Deletion (attack-pattern)
Used by threat actors
- Moses Staff (threat-actor)
Reports & references
- research.checkpoint.com — Mosesstaff Targeting Israeli Companies (report)
- MITRE ATT&CK — S1032 (report)