Threats Feed|Homeland Justice|Last Updated 24/04/2026|AuthorCertfa Radar|Publish Date30/12/2023

Analysis of Homeland Justice's Cyberattack on Albanian Government Infrastructure

  • Actor Motivations: Sabotage
  • Attack Vectors: Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

Homeland Justice, a politically motivated group emerging in mid-2022, has been linked to cyber attacks targeting the Albanian government and related entities. The group employs tactics such as the deployment of PowerShell scripts and .EXE files, with the former managing connectivity and remote operations and the latter potentially wiping host machine disks. Technical analysis of the payloads revealed sophisticated methods including remote execution, credential exploitation, and data destruction. These actions highlight the group's focus on disrupting Albanian government operations and exposing alleged corruption, signaling significant cyber threats to governmental sectors.

Detected Targets

TypeDescriptionConfidence
CaseParliament of Albania
The Parliament of Albania or Kuvendi is the unicameral representative body of the citizens of the Republic of Albania; it is Albania's legislature. Parliament of Albania has been targeted by Homeland Justice as the main target.
Verified
SectorGovernment Agencies and Services
Verified
RegionAlbania
Verified

Extracted IOCs

  • 36cc72c55f572fe02836f25516d18fed1de768e7f29af7bdf469b52a3fe2531f
  • c8b72d6416df83ee44134c779f70125cf1713d8797b0128ef591a7fe15674ac8
download

Tip: 2 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

Homeland JusticeHomeland Justice Wiper Attack Targets Albanian Telecoms and Government

Source: Clearsky - January 2024

Detection (one case): 36cc72c55f572fe02836f25516d18fed1de768e7f29af7bdf469b52a3fe2531f

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Homeland Justice Wiper Attack

An attack was launched against the Albanian parliament using malicious software designed to completely wipe and destroy the computer hard drives connected to their network.

A politically motivated group calling itself "Homeland Justice" claimed responsibility for the attack. They have been publicly active on social messaging platforms since mid-2022.

This was a destructive cyberattack intended to erase data and halt government operations. The attackers claim they are acting to expose corruption within the Albanian government and protest the country's support for a specific political party (Ashraf-3).

The attackers designed their tools to be highly scalable. They used an automated script to identify available computers on the network, copy the destructive software to all of them, and trigger the erasure process on multiple machines simultaneously.

Yes, this attack was highly specific. The target was the Albanian government, with this particular incident focusing on the computer systems of the Albanian parliament.

The attackers used a network script to scan for reachable computers and forcefully turned on remote management settings. They then copied a custom program to those computers that bypassed normal file protections to erase the core layout of the hard drives, effectively destroying all data.

The Albanian government was targeted strictly for ideological and political reasons. The attackers are using disruptive cyber operations as a form of protest against the state's domestic and foreign policies.

Organizations should heavily restrict who can run remote administrative commands on their networks. Additionally, they should deploy security software capable of detecting and blocking programs that attempt to make unauthorized, low-level modifications to computer hard drives.

This is a highly targeted incident aimed specifically at the Albanian government and its associated infrastructure, rather than a broad threat to the general public or standard businesses.

About Affiliation
Homeland Justice
Homeland Justice is an Iranian hacktivist persona linked to the IRGC responsible for destructive cyberattacks against Albania in 2022. The group targeted Albanian government infrastructure in retaliation for Albania hosting the Mojahedin-e Khalq (MEK) opposition group, deploying wiper malware disguised as ransomware to disrupt government services and border control systems. Albania attributed the attacks to Iran and expelled Iranian diplomats — a significant geopolitical consequence. Microsoft tracked the underlying operators as DEV-0842 before formal attribution to IRGC and MOIS-linked actors.
View Homeland Justice's Insights