Iranian Cyberattacks Disrupt Albanian Government Systems and Border Operations
- Actor Motivations: Espionage,Exfiltration,Extortion,Sabotage
- Attack Vectors: Brute-force,Security Misconfiguration,Vulnerability Exploitation,Ransomware,Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Iranian state-sponsored actors launched a series of cyberattacks against Albania, a NATO ally, targeting government systems. The initial attack on July 15, 2022, likely stemmed from Albania’s harboring of the Mujahedeen-e-Khalq (MEK) group. Subsequent attacks disrupted Albania’s Total Information Management System (TIMS), causing delays at borders and ports. Microsoft attributed the attack to Iranian-affiliated APTs, including EUROPIUM (APT34), using tools like ZeroCleare and Jason.exe for ransomware, data exfiltration, and disk wiping. The attacks leveraged vulnerabilities in public-facing applications and brute-force techniques. Albania severed diplomatic ties with Iran as a response, while the US condemned the attacks as a threat to NATO.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Albania | Verified |
FAQs
The Iranian Cyber Campaign Against Albania
Albania suffered major cyberattacks that briefly disabled government network access and temporarily shut down its national border data management system. Due to the severity of these state-sponsored attacks, the Albanian government took the unprecedented step of cutting diplomatic relations with Iran and expelling its diplomatic staff.
Cyber investigations linked the operations to threat groups sponsored by the Iranian government, including actors tied to Iran's Ministry of Intelligence and Security and the Islamic Revolutionary Guard Corps. Although Iranian officials denied involvement, international security agencies and law enforcement formally attributed the activity to Iranian actors and issued criminal charges against specific individuals.
The campaign combined long-term espionage, data theft, public exposure of stolen materials, and deliberate system destruction. The primary goals were to disrupt critical state operations, harass government leadership, and cause operational chaos across public services.
The intrusion spanned over a year, progressing from early system access and email theft to destructive wiping actions that crippled border processing. Security advisories noted that while this incident focused on Albania, the underlying Iranian threat groups actively target critical infrastructure in multiple allied nations, including the United States, Australia, Canada, and the United Kingdom.
Yes, the attackers specifically targeted Albanian government systems, Microsoft Exchange mailboxes, and border tracking operations. Sensitive personal email data belonging to the Prime Minister of Albania was also exfiltrated and leaked on public online forums.
Threat actors initially breached the network by exploiting an unpatched vulnerability in web server software and elevated their access using improperly configured administrator accounts. After spending months secretly harvesting email data, they launched malicious software designed to lock files, erase data, and take primary government networks offline.
Albania was targeted primarily due to geopolitical friction, specifically because the nation granted refuge to an Iranian opposition group known as the People's Mojahedin Organization of Iran. Attacking Albania's core government systems allowed the threat actors to retaliate against the country for its political actions.
This specific destructive campaign was a highly targeted strike aimed directly at Albania's public institutions and government operations. However, the threat groups responsible routinely conduct broader cyber operations against critical public and private organizations globally.
Organizations should regularly update and patch all software connected to the internet, strictly control and audit administrator account permissions, and enforce strong password policies. Maintaining off-site operational backups and implementing proactive network monitoring are essential steps to defend against similar destructive intrusions.