Cyber Espionage in Albania: Tracing the Links Between ROADSWEEP, CHIMNEYSWEEP, and Iranian Actors
- Actor Motivations: Disinformation,Espionage,Exfiltration,Sabotage
- Attack Vectors: Backdoor,Dropper,Keylogger,Ransomware,Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
In July 2022, Mandiant uncovered the ROADSWEEP ransomware, targeting the Albanian government with a politically motivated campaign. The operation, claimed by “HomeLand Justice,” disrupted Albanian government websites and services. This group also shared videos and documents suggesting ties to the Iranian opposition group MEK. Concurrently, CHIMNEYSWEEP, a backdoor linked to ROADSWEEP, was identified, targeting Farsi and Arabic speakers, including the Iranian diaspora, with capabilities like keylogging and file collection. Both ROADSWEEP and CHIMNEYSWEEP shared code and encryption methods. Additionally, a ZEROCLEAR wiper payload was reported, potentially linked to Iranian threat actors, known for targeting Middle Eastern entities.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Albania | Verified |
Extracted IOCs
- avira[.]ltd
- cloud-avira[.]com
- server-avira[.]com
- telegram-update[.]com
- uk2privat[.]com
- update-pgp[.]com
- update-real[.]com
- windowsupadates[.]com
- pgp.eu[.]com
- skype.se[.]net
- 19068e8228b6b8f5528489fa70779b2b
- 23643b7bd48a200889a4613a0e0a86e4
- 3633b3d69060a5882656b69f81655f0a
- 38e0fa41e9519d4783766992c203e794
- 3a1033cb1eb06c2cd5e91c539cf8a519
- 44d1c75815724523a58b566d95378825
- 49d72f9212d5653f5be9f764d8c9df24
- 5cc183702fae8cc23a55037c1efab5e5
- 779940f675ff4ab4e8cab7a1b7cf5d3c
- 77a369e5e49e7e62d8eef2c00cd02950
- 7a77c2930f0457ed2dd622e9739c7d3d
- 7b71764236f244ae971742ee1bc6b098
- 7f6db4493c6a76eb44534306291ea85f
- 8c8bbe3a4a23cd4cc96c12af5fb1199b
- 92c61e3047297136701c25deb658b35a
- 9c09d147dfbc98d5e6e051fe1ed0033d
- bbe983dba3bf319621b447618548b740
- df9ab47726001883b5fcf58b56b34b41
- f3c977830bf616b9061d7aee5ce0b2f2
- hxxp://avira[.]ltd/cm.php
- hxxp://cloud-avira[.]com/cm.php
- hxxp://pgp.eu[.]com/cm.php
- hxxp://server-avira[.]com/cm.php
- hxxp://skype.se[.]net/cm.php
- hxxp://telegram-update[.]com/cm.php
- hxxp://uk2privat[.]com/cm.php
- hxxp://update-pgp[.]com/cm.php
- hxxp://update-real[.]com/cm.php
- hxxp://windowsupadates[.]com/cm.php
Tip: 39 related IOCs (0 IP, 10 domain, 10 URL, 0 email, 19 file hash) to this threat have been found.
Overlaps
Source: Cybersecurity and Infrastructure Security Agency (CISA) - September 2022
Detection (two cases): 7b71764236f244ae971742ee1bc6b098, bbe983dba3bf319621b447618548b740
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Albanian Government Cyberattack
The Albanian government suffered a disruptive cyberattack that forced the temporary shutdown of online public services and government websites. During the incident, attackers deployed a politically motivated ransomware called ROADSWEEP and a highly destructive file-wiping malware called ZEROCLEAR.
A group calling itself "HomeLand Justice" publicly claimed responsibility for the attack through a dedicated website and a Telegram channel. Cybersecurity researchers also noted that the tools used, such as the CHIMNEYSWEEP backdoor, have historically been linked to threat actors operating out of Iran.
This attack was primarily politically motivated rather than driven by financial extortion. The threat actors intended to paralyze Albanian government systems, destroy data, and publicly leak sensitive internal documents to make a political statement.
The attack broadly impacted Albanian government digital infrastructure, taking vital citizen services and online portals offline. It also resulted in the theft and public exposure of internal government files, passports, and personal marriage certificates.
Yes, the attackers specifically targeted the Albanian government and members of an Iranian opposition group known as the MEK. The ransom notes and leaked documents focused on MEK members residing in Albania, directly criticizing the host nation for supporting them.
The attackers gained access to the network and used legitimate but compromised digital certificates to disguise their malicious software. Once inside, they disabled system recovery features, encrypted important files, and established a hidden backdoor using the Telegram messaging app to remotely control the infected computers.
Albania was likely targeted because it hosts members of the MEK and was preparing to hold the "World Summit of Free Iran" conference. The attackers sought to disrupt this event and punish the nation for harboring political opposition figures.
Organizations should continuously monitor their networks for unauthorized messaging app traffic, such as Telegram, on critical business servers. Additionally, security teams must keep software up-to-date, heavily restrict administrator privileges, and maintain secure, offline backups to recover from potential ransomware or data wiper attacks.
This was a highly targeted operation aimed specifically at the Albanian government and the MEK opposition group. However, the sophisticated techniques used serve as a warning for other organizations about the destructive potential of politically motivated cyber warfare.