Iranian State Actors Conduct Cyber Operations Against the Government of Albania
Cosa significa
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian State Actors Conduct Cyber Operations Against the Government of Albania. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Perché conta
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Azioni consigliate
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory Iranian State Actors Conduct Cyber Operations Against the Government of Albania Last Revised September 23, 2022 Alert Code AA22-264A Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory to provide information on recent cyber operations against the Government of Albania in July and September. This advisory provides a timeline of activity observed, from initial access to execution of encryption and wiper attacks. Additional information concerning files used by the actors during their exploitation of and cyber attack against the victim organization is provided in Appendices A and B. In July 2022, Iranian state cyber actors—identifying as “HomeLand Justice”—launched a destructive cyber attack against the Government of Albania which rendered websites and services unavailable. A FBI investigation indicates Iranian state cyber actors acquired initial access to the victim’s network approximately 14 months before launching the destructive cyber attack, which included a ransomware-style file encryptor and disk wiping malware. The actors maintained continuous network access for approximately a year, periodically accessing and exfiltrating e-mail content. Between May and June 2022, Iranian state cyber actors conducted lateral movements, network reconnaissance, and credential harvesting from Albanian government networks. In July 2022, the actors launched ransomware on the networks, leaving an anti-Mujahideen E-Khalq (MEK) message on desktops. When network defenders identified and began to respond to the ranso
Indicatori CISA verificabili
39 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T05:30:29.096774+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| MD5 | 59a85e8ec23ef5b5c215cd5c8e5bc2ab | |
| MD5 | 78562ba0069d4235f28efd01e3f32a82 | mellona.exe |
| MD5 | 8f766dea3afd410ebcd5df5994a3c571 | |
| MD5 | 81e123351eb80e605ad73268a5653ff3 | |
| MD5 | e9b6ecbf0783fa9d6981bba76d949c94 | App_Web_bckwssht.dll |
| SHA-1 | 49fd8de33aa0ea0c7432d62f1ddca832fab25325 | App_Web_bckwssht.dll |
| SHA-256 | cad2bc224108142b5aa19d787c19df236b0d12c779273d05f9b0298a63dc1fe5 | App_Web_bckwssht.dll |
| SSDEEP | 384:coY4jnD7l9VAk1dtrGBlLGYEX1tah8dgNyamGOvMTfdYN5qZAsP:hlXAkHRGBlUUh8cFmpv6feYLP | App_Web_bckwssht.dll |
| MD5 | a9fa6cfdba41c57d8094545e9b56db36 | ClientBin.aspx |
| SHA-1 | e03edd9114e7a0138d1309034cad6b461ab0035b | ClientBin.aspx |
| SHA-256 | 7ad64b64e0a4e510be42ba631868bbda8779139dc0daad9395ab048306cc83c5 | ClientBin.aspx |
| MD5 | 1635e1acd72809479e21b0ac5497a79b | win.bat |
| SHA-1 | 14b8c155e01f25e749a9726958606b242c8624b9 | win.bat |
| SHA-256 | bad65769c0b416bb16a82b5be11f1d4788239f8b2ba77ae57948b53a69e230a6 | win.bat |
| SSDEEP | 3:LjTFKCkRErG+fyM1KDCFUF82G:r0aH1+DF82G | win.bat |
| MD5 | 8f6e7653807ebb57ecc549cef991d505 | rwdsk.sys |
| SHA-1 | 5e061701b14faf9adec9dd0b2423ff3cfc18764b | rwdsk.sys |
| SHA-256 | 3c9dc8ada56adf9cebfc501a2d3946680dcb0534a137e2e27a7fcb5994cd9de6 | rwdsk.sys |
| SSDEEP | 768:E31ySCpoCbXnfDbEaJSooKIDyE9aBazWlEAusxsia:0gyCb3MFKIHO4Ausxta | rwdsk.sys |
| MD5 | 60afb1e62ac61424a542b8c7b4d2cf01 | disable-defender.exe |
| SHA-1 | e866cc6b1507f21f688ecc2ef15a64e413743da7 | disable-defender.exe |
| SHA-256 | 45bf0057b3121c6e444b316afafdd802d16083282d1cbfde3cdbf2a9d0915ace | disable-defender.exe |
| SSDEEP | 6144:t2WhikbJZc+Wrbe/t1zT/p03BuGJ1oh7ISCLun:t2WpZnW+/tVoJ1 | disable-defender.exe |
| MD5 | 7b71764236f244ae971742ee1bc6b098 | cl.exe |
| SHA-1 | f22a7ec80fbfdc4d8ed796119c76bfac01e0a908 | cl.exe |
| SHA-256 | e1204ebbd8f15dbf5f2e41dddc5337e3182fc4daf75b05acc948b8b965480ca0 | cl.exe |
| SSDEEP | 3072:vv2ADi7yOcE/YMBSZ0fZX4kpK1OhJrDwM:vv2jeQ/flfZbKM | cl.exe |
| MD5 | 18e01dee14167c1cf8a58b6a648ee049 | win.bat |
| SHA-1 | fce0db6e66d227d3b82d4564446ede0c0fd7598c | win.bat |
| SHA-256 | ec4cd040fd14bff86f6f6e7ba357e5bcf150c455532800edf97782836e97f6d2 | win.bat |
| SSDEEP | 12:wbYVJ69/TsdLd6sdLd3mTDwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+Et:wq69/kZxZ3mTDY9HY9HY9HY9HY9j | win.bat |
| MD5 | 0738242a521bdfe1f3ecc173f1726aa1 | goxml.jpg |
| SHA-1 | 683eaec2b3bb5436f00b2172e287dc95e2ff2266 | goxml.jpg |
| SHA-256 | 63dd02c371e84323c4fd9a161a75e0f525423219e8a6ec1b95dd9eda182af2c9 | goxml.jpg |
| SSDEEP | 12288:ME0p1RE70zxntT/ylTyaaSMn2fS+0M6puxKfJbDKrCxMe5fPSC2tmxVjpJT/n37p:MHyUt7yQaaPXS6pjar+MwrjpJ7VIbZg | goxml.jpg |
| MD5 | bbe983dba3bf319621b447618548b740 | GoXml.exe |
| SHA-1 | 5d117d8ef075f3f8ed1d4edcc0771a2a0886a376 | GoXml.exe |
| SHA-256 | f116acc6508843f59e59fb5a8d643370dce82f492a217764521f46a856cc4cb5 | GoXml.exe |
| SSDEEP | 768:+OFu8Q3w6QzfR5Jni6SQD7qSFDs6P93/q0XIc/UB5EPABWX:RFu8QAFzffJui79f13/AnB5EPAkX | GoXml.exe |
Provenienza
Allegato ufficiale CISA · 2022-09-23T19:13:10Z
SHA-512: d8af448a49096b33ae821305f46b30e5d54aa2e4738851fae9220afe8a1a88b34af69374638ec8944bc0d326092506a780ae73802bf99b63ceee6ccf9aa6baa0
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 23/09/2022 14:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1003.001, T1021.001, T1021.002, T1027, T1059.003, T1068, T1071, T1112, T1136, T1140, T1190, T1486, T1561, T1567, T1590
- CVE
- CVE-2019-0604
- Classificazione
- Critica
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.