Threats Feed|Homeland Justice|Last Updated 24/07/2026|AuthorCertfa Radar|Publish Date04/08/2022

Cyber Espionage in Albania: Tracing the Links Between ROADSWEEP, CHIMNEYSWEEP, and Iranian Actors

  • Actor Motivations: Disinformation,Espionage,Exfiltration,Sabotage
  • Attack Vectors: Backdoor,Dropper,Keylogger,Ransomware,Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

In July 2022, Mandiant uncovered the ROADSWEEP ransomware, targeting the Albanian government with a politically motivated campaign. The operation, claimed by “HomeLand Justice,” disrupted Albanian government websites and services. This group also shared videos and documents suggesting ties to the Iranian opposition group MEK. Concurrently, CHIMNEYSWEEP, a backdoor linked to ROADSWEEP, was identified, targeting Farsi and Arabic speakers, including the Iranian diaspora, with capabilities like keylogging and file collection. Both ROADSWEEP and CHIMNEYSWEEP shared code and encryption methods. Additionally, a ZEROCLEAR wiper payload was reported, potentially linked to Iranian threat actors, known for targeting Middle Eastern entities.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionAlbania
Verified

Extracted IOCs

  • avira[.]ltd
  • cloud-avira[.]com
  • server-avira[.]com
  • telegram-update[.]com
  • uk2privat[.]com
  • update-pgp[.]com
  • update-real[.]com
  • windowsupadates[.]com
  • pgp.eu[.]com
  • skype.se[.]net
  • 19068e8228b6b8f5528489fa70779b2b
  • 23643b7bd48a200889a4613a0e0a86e4
  • 3633b3d69060a5882656b69f81655f0a
  • 38e0fa41e9519d4783766992c203e794
  • 3a1033cb1eb06c2cd5e91c539cf8a519
  • 44d1c75815724523a58b566d95378825
  • 49d72f9212d5653f5be9f764d8c9df24
  • 5cc183702fae8cc23a55037c1efab5e5
  • 779940f675ff4ab4e8cab7a1b7cf5d3c
  • 77a369e5e49e7e62d8eef2c00cd02950
  • 7a77c2930f0457ed2dd622e9739c7d3d
  • 7b71764236f244ae971742ee1bc6b098
  • 7f6db4493c6a76eb44534306291ea85f
  • 8c8bbe3a4a23cd4cc96c12af5fb1199b
  • 92c61e3047297136701c25deb658b35a
  • 9c09d147dfbc98d5e6e051fe1ed0033d
  • bbe983dba3bf319621b447618548b740
  • df9ab47726001883b5fcf58b56b34b41
  • f3c977830bf616b9061d7aee5ce0b2f2
  • hxxp://avira[.]ltd/cm.php
  • hxxp://cloud-avira[.]com/cm.php
  • hxxp://pgp.eu[.]com/cm.php
  • hxxp://server-avira[.]com/cm.php
  • hxxp://skype.se[.]net/cm.php
  • hxxp://telegram-update[.]com/cm.php
  • hxxp://uk2privat[.]com/cm.php
  • hxxp://update-pgp[.]com/cm.php
  • hxxp://update-real[.]com/cm.php
  • hxxp://windowsupadates[.]com/cm.php
download

Tip: 39 related IOCs (0 IP, 10 domain, 10 URL, 0 email, 19 file hash) to this threat have been found.

Overlaps

Homeland Justice"HomeLand Justice" Cyber Campaign Disrupts Albanian Government Operations

Source: Cybersecurity and Infrastructure Security Agency (CISA) - September 2022

Detection (two cases): 7b71764236f244ae971742ee1bc6b098, bbe983dba3bf319621b447618548b740

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Albanian Government Cyberattack

The Albanian government suffered a disruptive cyberattack that forced the temporary shutdown of online public services and government websites. During the incident, attackers deployed a politically motivated ransomware called ROADSWEEP and a highly destructive file-wiping malware called ZEROCLEAR.

A group calling itself "HomeLand Justice" publicly claimed responsibility for the attack through a dedicated website and a Telegram channel. Cybersecurity researchers also noted that the tools used, such as the CHIMNEYSWEEP backdoor, have historically been linked to threat actors operating out of Iran.

This attack was primarily politically motivated rather than driven by financial extortion. The threat actors intended to paralyze Albanian government systems, destroy data, and publicly leak sensitive internal documents to make a political statement.

The attack broadly impacted Albanian government digital infrastructure, taking vital citizen services and online portals offline. It also resulted in the theft and public exposure of internal government files, passports, and personal marriage certificates.

Yes, the attackers specifically targeted the Albanian government and members of an Iranian opposition group known as the MEK. The ransom notes and leaked documents focused on MEK members residing in Albania, directly criticizing the host nation for supporting them.

The attackers gained access to the network and used legitimate but compromised digital certificates to disguise their malicious software. Once inside, they disabled system recovery features, encrypted important files, and established a hidden backdoor using the Telegram messaging app to remotely control the infected computers.

Albania was likely targeted because it hosts members of the MEK and was preparing to hold the "World Summit of Free Iran" conference. The attackers sought to disrupt this event and punish the nation for harboring political opposition figures.

Organizations should continuously monitor their networks for unauthorized messaging app traffic, such as Telegram, on critical business servers. Additionally, security teams must keep software up-to-date, heavily restrict administrator privileges, and maintain secure, offline backups to recover from potential ransomware or data wiper attacks.

This was a highly targeted operation aimed specifically at the Albanian government and the MEK opposition group. However, the sophisticated techniques used serve as a warning for other organizations about the destructive potential of politically motivated cyber warfare.

About Affiliation
Homeland Justice
Homeland Justice is an Iranian hacktivist persona linked to the IRGC responsible for destructive cyberattacks against Albania in 2022. The group targeted Albanian government infrastructure in retaliation for Albania hosting the Mojahedin-e Khalq (MEK) opposition group, deploying wiper malware disguised as ransomware to disrupt government services and border control systems. Albania attributed the attacks to Iran and expelled Iranian diplomats — a significant geopolitical consequence. Microsoft tracked the underlying operators as DEV-0842 before formal attribution to IRGC and MOIS-linked actors.
View Homeland Justice's Insights