Analysis of Homeland Justice's Cyberattack on Albanian Government Infrastructure
- Actor Motivations: Sabotage
- Attack Vectors: Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
Homeland Justice, a politically motivated group emerging in mid-2022, has been linked to cyber attacks targeting the Albanian government and related entities. The group employs tactics such as the deployment of PowerShell scripts and .EXE files, with the former managing connectivity and remote operations and the latter potentially wiping host machine disks. Technical analysis of the payloads revealed sophisticated methods including remote execution, credential exploitation, and data destruction. These actions highlight the group's focus on disrupting Albanian government operations and exposing alleged corruption, signaling significant cyber threats to governmental sectors.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Parliament of Albania The Parliament of Albania or Kuvendi is the unicameral representative body of the citizens of the Republic of Albania; it is Albania's legislature. Parliament of Albania has been targeted by Homeland Justice as the main target. | Verified |
| Sector | Government Agencies and Services | Verified |
| Region | Albania | Verified |
Extracted IOCs
- 36cc72c55f572fe02836f25516d18fed1de768e7f29af7bdf469b52a3fe2531f
- c8b72d6416df83ee44134c779f70125cf1713d8797b0128ef591a7fe15674ac8
Tip: 2 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.
Overlaps
Source: Clearsky - January 2024
Detection (one case): 36cc72c55f572fe02836f25516d18fed1de768e7f29af7bdf469b52a3fe2531f
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Homeland Justice Wiper Attack
An attack was launched against the Albanian parliament using malicious software designed to completely wipe and destroy the computer hard drives connected to their network.
A politically motivated group calling itself "Homeland Justice" claimed responsibility for the attack. They have been publicly active on social messaging platforms since mid-2022.
This was a destructive cyberattack intended to erase data and halt government operations. The attackers claim they are acting to expose corruption within the Albanian government and protest the country's support for a specific political party (Ashraf-3).
The attackers designed their tools to be highly scalable. They used an automated script to identify available computers on the network, copy the destructive software to all of them, and trigger the erasure process on multiple machines simultaneously.
Yes, this attack was highly specific. The target was the Albanian government, with this particular incident focusing on the computer systems of the Albanian parliament.
The attackers used a network script to scan for reachable computers and forcefully turned on remote management settings. They then copied a custom program to those computers that bypassed normal file protections to erase the core layout of the hard drives, effectively destroying all data.
The Albanian government was targeted strictly for ideological and political reasons. The attackers are using disruptive cyber operations as a form of protest against the state's domestic and foreign policies.
Organizations should heavily restrict who can run remote administrative commands on their networks. Additionally, they should deploy security software capable of detecting and blocking programs that attempt to make unauthorized, low-level modifications to computer hard drives.
This is a highly targeted incident aimed specifically at the Albanian government and its associated infrastructure, rather than a broad threat to the general public or standard businesses.