EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

Iranian State Actors Conduct Cyber Operations Against the Government of Albania

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian State Actors Conduct Cyber Operations Against the Government of Albania. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory Iranian State Actors Conduct Cyber Operations Against the Government of Albania Last Revised September 23, 2022 Alert Code AA22-264A Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory to provide information on recent cyber operations against the Government of Albania in July and September. This advisory provides a timeline of activity observed, from initial access to execution of encryption and wiper attacks. Additional information concerning files used by the actors during their exploitation of and cyber attack against the victim organization is provided in Appendices A and B. In July 2022, Iranian state cyber actors—identifying as “HomeLand Justice”—launched a destructive cyber attack against the Government of Albania which rendered websites and services unavailable. A FBI investigation indicates Iranian state cyber actors acquired initial access to the victim’s network approximately 14 months before launching the destructive cyber attack, which included a ransomware-style file encryptor and disk wiping malware. The actors maintained continuous network access for approximately a year, periodically accessing and exfiltrating e-mail content. Between May and June 2022, Iranian state cyber actors conducted lateral movements, network reconnaissance, and credential harvesting from Albanian government networks. In July 2022, the actors launched ransomware on the networks, leaving an anti-Mujahideen E-Khalq (MEK) message on desktops. When network defenders identified and began to respond to the ranso

Indicatori CISA verificabili

39 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T05:30:29.096774+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
MD559a85e8ec23ef5b5c215cd5c8e5bc2ab
MD578562ba0069d4235f28efd01e3f32a82mellona.exe
MD58f766dea3afd410ebcd5df5994a3c571
MD581e123351eb80e605ad73268a5653ff3
MD5e9b6ecbf0783fa9d6981bba76d949c94App_Web_bckwssht.dll
SHA-149fd8de33aa0ea0c7432d62f1ddca832fab25325App_Web_bckwssht.dll
SHA-256cad2bc224108142b5aa19d787c19df236b0d12c779273d05f9b0298a63dc1fe5App_Web_bckwssht.dll
SSDEEP384:coY4jnD7l9VAk1dtrGBlLGYEX1tah8dgNyamGOvMTfdYN5qZAsP:hlXAkHRGBlUUh8cFmpv6feYLPApp_Web_bckwssht.dll
MD5a9fa6cfdba41c57d8094545e9b56db36ClientBin.aspx
SHA-1e03edd9114e7a0138d1309034cad6b461ab0035bClientBin.aspx
SHA-2567ad64b64e0a4e510be42ba631868bbda8779139dc0daad9395ab048306cc83c5ClientBin.aspx
MD51635e1acd72809479e21b0ac5497a79bwin.bat
SHA-114b8c155e01f25e749a9726958606b242c8624b9win.bat
SHA-256bad65769c0b416bb16a82b5be11f1d4788239f8b2ba77ae57948b53a69e230a6win.bat
SSDEEP3:LjTFKCkRErG+fyM1KDCFUF82G:r0aH1+DF82Gwin.bat
MD58f6e7653807ebb57ecc549cef991d505rwdsk.sys
SHA-15e061701b14faf9adec9dd0b2423ff3cfc18764brwdsk.sys
SHA-2563c9dc8ada56adf9cebfc501a2d3946680dcb0534a137e2e27a7fcb5994cd9de6rwdsk.sys
SSDEEP768:E31ySCpoCbXnfDbEaJSooKIDyE9aBazWlEAusxsia:0gyCb3MFKIHO4Ausxtarwdsk.sys
MD560afb1e62ac61424a542b8c7b4d2cf01disable-defender.exe
SHA-1e866cc6b1507f21f688ecc2ef15a64e413743da7disable-defender.exe
SHA-25645bf0057b3121c6e444b316afafdd802d16083282d1cbfde3cdbf2a9d0915acedisable-defender.exe
SSDEEP6144:t2WhikbJZc+Wrbe/t1zT/p03BuGJ1oh7ISCLun:t2WpZnW+/tVoJ1disable-defender.exe
MD57b71764236f244ae971742ee1bc6b098cl.exe
SHA-1f22a7ec80fbfdc4d8ed796119c76bfac01e0a908cl.exe
SHA-256e1204ebbd8f15dbf5f2e41dddc5337e3182fc4daf75b05acc948b8b965480ca0cl.exe
SSDEEP3072:vv2ADi7yOcE/YMBSZ0fZX4kpK1OhJrDwM:vv2jeQ/flfZbKMcl.exe
MD518e01dee14167c1cf8a58b6a648ee049win.bat
SHA-1fce0db6e66d227d3b82d4564446ede0c0fd7598cwin.bat
SHA-256ec4cd040fd14bff86f6f6e7ba357e5bcf150c455532800edf97782836e97f6d2win.bat
SSDEEP12:wbYVJ69/TsdLd6sdLd3mTDwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+Et:wq69/kZxZ3mTDY9HY9HY9HY9HY9jwin.bat
MD50738242a521bdfe1f3ecc173f1726aa1goxml.jpg
SHA-1683eaec2b3bb5436f00b2172e287dc95e2ff2266goxml.jpg
SHA-25663dd02c371e84323c4fd9a161a75e0f525423219e8a6ec1b95dd9eda182af2c9goxml.jpg
SSDEEP12288:ME0p1RE70zxntT/ylTyaaSMn2fS+0M6puxKfJbDKrCxMe5fPSC2tmxVjpJT/n37p:MHyUt7yQaaPXS6pjar+MwrjpJ7VIbZggoxml.jpg
MD5bbe983dba3bf319621b447618548b740GoXml.exe
SHA-15d117d8ef075f3f8ed1d4edcc0771a2a0886a376GoXml.exe
SHA-256f116acc6508843f59e59fb5a8d643370dce82f492a217764521f46a856cc4cb5GoXml.exe
SSDEEP768:+OFu8Q3w6QzfR5Jni6SQD7qSFDs6P93/q0XIc/UB5EPABWX:RFu8QAFzffJui79f13/AnB5EPAkXGoXml.exe

Provenienza

Allegato ufficiale CISA · 2022-09-23T19:13:10Z

SHA-512: d8af448a49096b33ae821305f46b30e5d54aa2e4738851fae9220afe8a1a88b34af69374638ec8944bc0d326092506a780ae73802bf99b63ceee6ccf9aa6baa0

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
23/09/2022 14:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1003.001, T1021.001, T1021.002, T1027, T1059.003, T1068, T1071, T1112, T1136, T1140, T1190, T1486, T1561, T1567, T1590
CVE
CVE-2019-0604
Classificazione
Critica
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale