Back to Threat Groups

Abrahams_Ax

ACTIVE

ransomware group

Abrahams_Ax, first observed in November 2022, is not a Ransomware-as-a-Service (RaaS) operation but a politically motivated hacktivist persona. The group is linked to the Iranian-associated threat actor COBALT SAPLING, which previously operated as Moses Staff. It uses double-extortion tactics focused on stealing and leaking sensitive data rather than encrypting files. Infrastructure, visual branding, and operational patterns strongly resemble those of Moses Staff, suggesting a shared origin. Its most notable incident was the breach of the Saudi Arabian Ministry of Interior, where stolen data was published alongside propaganda content. The group’s targeting appears to align with Middle Eastern geopolitical interests, particularly against Israeli- and Saudi-linked entities. No encryption methods or file extensions are publicly documented, as encryption is not part of their operations.

Victims
0
records
First Discovered
Dec 31, 2024
victim
Last Discovered
Jun 21, 2026
victim
Inactive Since
Countries
0
hit
Avg Discount
no settlements

Group Activity

Last 12 months
Jul
2025
Aug
2025
Sep
2025
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026

Victims (0)

No victims recorded

Infrastructure

leak site
OFFLINE
http://abrahams-ax.se

never crawled

leak site
OFFLINE
http://abrahamm32umasogaqojib3ey2w2nwoafffrguq43tsyke4s3fz3w4yd.onion

never crawled