ATT&CKCampaignsHomeLand Justice

HomeLand Justice

C0038

Campaign, May 2021 to Sep 2022.View on attack.mitre.org

About this campaign

HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for HomeLand Justice was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including HEXANE who probed victim infrastructure. A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1003.001
LSASS Memory

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

T1021.001
Remote Desktop Protocol

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.002
SMB/Windows Admin Shares

During HomeLand Justice, threat actors used SMB for lateral movement.

T1036.005
Match Legitimate Resource Name or Location

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1041
Exfiltration Over C2 Channel

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

T1046
Network Service Discovery

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

T1047
Windows Management Instrumentation

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

T1059.001
PowerShell

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.003
Windows Command Shell

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1078
Valid Accounts

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

T1078.001
Default Accounts

During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket.

T1087.003
Email Account

During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts.

T1098.002
Additional Email Delegate Permissions

During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes.

T1105
Ingress Tool Transfer

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.

T1114.002
Remote Email Collection

During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data.

View all 25 procedure examples

Attributed groups1

Software7

References3

  1. CISA Iran Albanian Attacks September 2022 Open source
    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.
  2. Mandiant ROADSWEEP August 2022 Open source
    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.
  3. Microsoft Albanian Government Attacks September 2022 Open source
    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.