EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Iranian State Actors Conduct Cyber Operations Against the Government of Albania

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian State Actors Conduct Cyber Operations Against the Government of Albania. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory Iranian State Actors Conduct Cyber Operations Against the Government of Albania Last Revised September 23, 2022 Alert Code AA22-264A Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory to provide information on recent cyber operations against the Government of Albania in July and September. This advisory provides a timeline of activity observed, from initial access to execution of encryption and wiper attacks. Additional information concerning files used by the actors during their exploitation of and cyber attack against the victim organization is provided in Appendices A and B. In July 2022, Iranian state cyber actors—identifying as “HomeLand Justice”—launched a destructive cyber attack against the Government of Albania which rendered websites and services unavailable. A FBI investigation indicates Iranian state cyber actors acquired initial access to the victim’s network approximately 14 months before launching the destructive cyber attack, which included a ransomware-style file encryptor and disk wiping malware. The actors maintained continuous network access for approximately a year, periodically accessing and exfiltrating e-mail content. Between May and June 2022, Iranian state cyber actors conducted lateral movements, network reconnaissance, and credential harvesting from Albanian government networks. In July 2022, the actors launched ransomware on the networks, leaving an anti-Mujahideen E-Khalq (MEK) message on desktops. When network defenders identified and began to respond to the ranso

Indicatori CISA verificabili

39 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T05:30:29.096774+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
MD559a85e8ec23ef5b5c215cd5c8e5bc2ab
MD578562ba0069d4235f28efd01e3f32a82mellona.exe
MD58f766dea3afd410ebcd5df5994a3c571
MD581e123351eb80e605ad73268a5653ff3
MD5e9b6ecbf0783fa9d6981bba76d949c94App_Web_bckwssht.dll
SHA-149fd8de33aa0ea0c7432d62f1ddca832fab25325App_Web_bckwssht.dll
SHA-256cad2bc224108142b5aa19d787c19df236b0d12c779273d05f9b0298a63dc1fe5App_Web_bckwssht.dll
SSDEEP384:coY4jnD7l9VAk1dtrGBlLGYEX1tah8dgNyamGOvMTfdYN5qZAsP:hlXAkHRGBlUUh8cFmpv6feYLPApp_Web_bckwssht.dll
MD5a9fa6cfdba41c57d8094545e9b56db36ClientBin.aspx
SHA-1e03edd9114e7a0138d1309034cad6b461ab0035bClientBin.aspx
SHA-2567ad64b64e0a4e510be42ba631868bbda8779139dc0daad9395ab048306cc83c5ClientBin.aspx
MD51635e1acd72809479e21b0ac5497a79bwin.bat
SHA-114b8c155e01f25e749a9726958606b242c8624b9win.bat
SHA-256bad65769c0b416bb16a82b5be11f1d4788239f8b2ba77ae57948b53a69e230a6win.bat
SSDEEP3:LjTFKCkRErG+fyM1KDCFUF82G:r0aH1+DF82Gwin.bat
MD58f6e7653807ebb57ecc549cef991d505rwdsk.sys
SHA-15e061701b14faf9adec9dd0b2423ff3cfc18764brwdsk.sys
SHA-2563c9dc8ada56adf9cebfc501a2d3946680dcb0534a137e2e27a7fcb5994cd9de6rwdsk.sys
SSDEEP768:E31ySCpoCbXnfDbEaJSooKIDyE9aBazWlEAusxsia:0gyCb3MFKIHO4Ausxtarwdsk.sys
MD560afb1e62ac61424a542b8c7b4d2cf01disable-defender.exe
SHA-1e866cc6b1507f21f688ecc2ef15a64e413743da7disable-defender.exe
SHA-25645bf0057b3121c6e444b316afafdd802d16083282d1cbfde3cdbf2a9d0915acedisable-defender.exe
SSDEEP6144:t2WhikbJZc+Wrbe/t1zT/p03BuGJ1oh7ISCLun:t2WpZnW+/tVoJ1disable-defender.exe
MD57b71764236f244ae971742ee1bc6b098cl.exe
SHA-1f22a7ec80fbfdc4d8ed796119c76bfac01e0a908cl.exe
SHA-256e1204ebbd8f15dbf5f2e41dddc5337e3182fc4daf75b05acc948b8b965480ca0cl.exe
SSDEEP3072:vv2ADi7yOcE/YMBSZ0fZX4kpK1OhJrDwM:vv2jeQ/flfZbKMcl.exe
MD518e01dee14167c1cf8a58b6a648ee049win.bat
SHA-1fce0db6e66d227d3b82d4564446ede0c0fd7598cwin.bat
SHA-256ec4cd040fd14bff86f6f6e7ba357e5bcf150c455532800edf97782836e97f6d2win.bat
SSDEEP12:wbYVJ69/TsdLd6sdLd3mTDwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+Et:wq69/kZxZ3mTDY9HY9HY9HY9HY9jwin.bat
MD50738242a521bdfe1f3ecc173f1726aa1goxml.jpg
SHA-1683eaec2b3bb5436f00b2172e287dc95e2ff2266goxml.jpg
SHA-25663dd02c371e84323c4fd9a161a75e0f525423219e8a6ec1b95dd9eda182af2c9goxml.jpg
SSDEEP12288:ME0p1RE70zxntT/ylTyaaSMn2fS+0M6puxKfJbDKrCxMe5fPSC2tmxVjpJT/n37p:MHyUt7yQaaPXS6pjar+MwrjpJ7VIbZggoxml.jpg
MD5bbe983dba3bf319621b447618548b740GoXml.exe
SHA-15d117d8ef075f3f8ed1d4edcc0771a2a0886a376GoXml.exe
SHA-256f116acc6508843f59e59fb5a8d643370dce82f492a217764521f46a856cc4cb5GoXml.exe
SSDEEP768:+OFu8Q3w6QzfR5Jni6SQD7qSFDs6P93/q0XIc/UB5EPABWX:RFu8QAFzffJui79f13/AnB5EPAkXGoXml.exe

Provenance

Allegato ufficiale CISA · 2022-09-23T19:13:10Z

SHA-512: d8af448a49096b33ae821305f46b30e5d54aa2e4738851fae9220afe8a1a88b34af69374638ec8944bc0d326092506a780ae73802bf99b63ceee6ccf9aa6baa0

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
23/09/2022 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1003.001, T1021.001, T1021.002, T1027, T1059.003, T1068, T1071, T1112, T1136, T1140, T1190, T1486, T1561, T1567, T1590
CVE
CVE-2019-0604
Classification
Critical
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source