high_confidence

HomeLand Justice

[HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for [HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including [HEXANE](https://attack.mitre.org/groups/G1001) who probed victim infrastructure.(Citation: Mandiant ROADSWEEP August 2022)(Citation: Microsoft Albanian Government Attacks September 2022)(Citation: CISA Iran Albanian Attacks September 2022) A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.(Citation: CISA Iran Albanian Attacks September 2022)

Start date
1 May 2021
End date
1 September 2022
Techniques
25

Attributed actors

Techniques (25)

collection1
T1114.002Remote Email Collection
command-and-control1
T1105Ingress Tool Transfer
credential-access1
T1003.001LSASS Memory
defense-impairment2
T1685Disable or Modify Tools
T1685.001Disable or Modify Windows Event Log
discovery2
T1046Network Service Discovery
T1087.003Email Account
execution3
T1059.003Windows Command Shell
T1047Windows Management Instrumentation
T1059.001PowerShell
exfiltration1
T1041Exfiltration Over C2 Channel
impact2
T1486Data Encrypted for Impact
T1561.002Disk Structure Wipe
initial-access3
T1078.001Default Accounts
T1078Valid Accounts
T1190Exploit Public-Facing Application
lateral-movement3
T1021.001Remote Desktop Protocol
T1570Lateral Tool Transfer
T1021.002SMB/Windows Admin Shares
persistence4
T1078.001Default Accounts
T1078Valid Accounts
T1505.003Web Shell
T1098.002Additional Email Delegate Permissions
privilege-escalation4
T1078.001Default Accounts
T1078Valid Accounts
T1134.001Token Impersonation/Theft
T1098.002Additional Email Delegate Permissions
resource-development2
T1588.002Tool
T1588.003Code Signing Certificates
stealth4
T1078.001Default Accounts
T1036.005Match Legitimate Resource Name or Location
T1078Valid Accounts
T1134.001Token Impersonation/Theft

Indicators of compromise

No IOCs linked to this campaign yet.

HomeLand Justice — Campaign | Fancy Intel