Actors Insights|Latest update30/07/2026

DEV-0842

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

DEV-0842 is a Microsoft temporary designation for the Iranian threat actors behind the July 2022 destructive cyberattack against Albanian government infrastructure, later formally attributed to IRGC and MOIS operators acting under the Homeland Justice persona. Microsoft attributed the attack based on the use of ZeroCleare wiper malware combined with ransomware as a cover for destruction, and noted the operators had maintained access to Albanian networks for months before deploying the payload. The DEV-0842 designation has since been retired as the activity was formally attributed to Iran's state intelligence apparatus.

First Seen:Jul 2022
Last Seen:Sep 2022
Indexed Reports:1
Public IOCs:0
also known as:
DEV-0842 (Microsoft)

Targeted Regions

Albania
AL
Albania
Albania
Jul 2022 ~ Sep 2022
Jul 2022 ~ Sep 2022
Jan 2022Nov 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.