Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

CISA, FBI Detail Iranian Cyberattacks Targeting Albanian Government

Iranian hackers breached Albanian government one year before disruptive attacks

Iranian hackers breached Albanian government one year before disruptive attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint advisory detailing the cyberattacks that Iranian threat actors conducted against the Albanian government in July 2022.

Attributed to state-sponsored Iranian advanced persistent threat (ATP) actors referred to as ‘HomeLand Justice’, the attack disrupted the Albanian government’s websites and services.

As a result of the incident, Albania cut diplomatic ties with Iran and the US announced sanctions against entities in Iran. According to Microsoft, at least four different Iranian threat actors were involved in the hacks.

In a joint advisory this week, CISA and the FBI have shared details on the timeline of activity associated with the incident, as well as technical information on some of the files the hackers used during the attack.

According to the two agencies, the attackers had access to the Albanian government’s network for roughly 14 months before launching the crippling attack, which involved both ransomware and a wiper.

Advertisement. Scroll to continue reading.

During this timeframe, the attackers periodically accessed compromised email accounts, exfiltrated emails, and conducted credential harvesting, lateral movement, and network reconnaissance.

In July 2022, the adversaries deployed ransomware on compromised systems and left anti-Mujahideen E-Khalq (MEK) messages on multiple computer desktops. They also deployed a variant of the ZeroCleare destructive malware.

In addition to ransomware and wiping malware, the attackers were observed using multiple webshells for persistence, as well as relying on RDP, SMB, and FTP for lateral movement. They also connected to IPs associated with the victim’s VPN and used Mimikatz for credential dumping.

In September 2022, after Albania publicly attributed the July attacks to Iran, the threat actors launched a new wave of assaults against the Albanian government, using similar TTPs and malware, CISA and the FBI note.

Related: NATO’s Team in Albania to Help on Iran-Alleged Cyberattack

Related: US Indicts Iranians Who Hacked Power Company, Women’s Shelter

Related: US, UK, Canada and Australia Link Iranian Government Agency to Ransomware Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.