Iranian State Actors Conduct Cyber Operations Against the Government of Albania
What it means
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian State Actors Conduct Cyber Operations Against the Government of Albania. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Why it matters
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Recommended actions
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Potential operational benefits
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory Iranian State Actors Conduct Cyber Operations Against the Government of Albania Last Revised September 23, 2022 Alert Code AA22-264A Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory to provide information on recent cyber operations against the Government of Albania in July and September. This advisory provides a timeline of activity observed, from initial access to execution of encryption and wiper attacks. Additional information concerning files used by the actors during their exploitation of and cyber attack against the victim organization is provided in Appendices A and B. In July 2022, Iranian state cyber actors—identifying as “HomeLand Justice”—launched a destructive cyber attack against the Government of Albania which rendered websites and services unavailable. A FBI investigation indicates Iranian state cyber actors acquired initial access to the victim’s network approximately 14 months before launching the destructive cyber attack, which included a ransomware-style file encryptor and disk wiping malware. The actors maintained continuous network access for approximately a year, periodically accessing and exfiltrating e-mail content. Between May and June 2022, Iranian state cyber actors conducted lateral movements, network reconnaissance, and credential harvesting from Albanian government networks. In July 2022, the actors launched ransomware on the networks, leaving an anti-Mujahideen E-Khalq (MEK) message on desktops. When network defenders identified and began to respond to the ranso
Indicatori CISA verificabili
39 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T05:30:29.096774+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| MD5 | 59a85e8ec23ef5b5c215cd5c8e5bc2ab | |
| MD5 | 78562ba0069d4235f28efd01e3f32a82 | mellona.exe |
| MD5 | 8f766dea3afd410ebcd5df5994a3c571 | |
| MD5 | 81e123351eb80e605ad73268a5653ff3 | |
| MD5 | e9b6ecbf0783fa9d6981bba76d949c94 | App_Web_bckwssht.dll |
| SHA-1 | 49fd8de33aa0ea0c7432d62f1ddca832fab25325 | App_Web_bckwssht.dll |
| SHA-256 | cad2bc224108142b5aa19d787c19df236b0d12c779273d05f9b0298a63dc1fe5 | App_Web_bckwssht.dll |
| SSDEEP | 384:coY4jnD7l9VAk1dtrGBlLGYEX1tah8dgNyamGOvMTfdYN5qZAsP:hlXAkHRGBlUUh8cFmpv6feYLP | App_Web_bckwssht.dll |
| MD5 | a9fa6cfdba41c57d8094545e9b56db36 | ClientBin.aspx |
| SHA-1 | e03edd9114e7a0138d1309034cad6b461ab0035b | ClientBin.aspx |
| SHA-256 | 7ad64b64e0a4e510be42ba631868bbda8779139dc0daad9395ab048306cc83c5 | ClientBin.aspx |
| MD5 | 1635e1acd72809479e21b0ac5497a79b | win.bat |
| SHA-1 | 14b8c155e01f25e749a9726958606b242c8624b9 | win.bat |
| SHA-256 | bad65769c0b416bb16a82b5be11f1d4788239f8b2ba77ae57948b53a69e230a6 | win.bat |
| SSDEEP | 3:LjTFKCkRErG+fyM1KDCFUF82G:r0aH1+DF82G | win.bat |
| MD5 | 8f6e7653807ebb57ecc549cef991d505 | rwdsk.sys |
| SHA-1 | 5e061701b14faf9adec9dd0b2423ff3cfc18764b | rwdsk.sys |
| SHA-256 | 3c9dc8ada56adf9cebfc501a2d3946680dcb0534a137e2e27a7fcb5994cd9de6 | rwdsk.sys |
| SSDEEP | 768:E31ySCpoCbXnfDbEaJSooKIDyE9aBazWlEAusxsia:0gyCb3MFKIHO4Ausxta | rwdsk.sys |
| MD5 | 60afb1e62ac61424a542b8c7b4d2cf01 | disable-defender.exe |
| SHA-1 | e866cc6b1507f21f688ecc2ef15a64e413743da7 | disable-defender.exe |
| SHA-256 | 45bf0057b3121c6e444b316afafdd802d16083282d1cbfde3cdbf2a9d0915ace | disable-defender.exe |
| SSDEEP | 6144:t2WhikbJZc+Wrbe/t1zT/p03BuGJ1oh7ISCLun:t2WpZnW+/tVoJ1 | disable-defender.exe |
| MD5 | 7b71764236f244ae971742ee1bc6b098 | cl.exe |
| SHA-1 | f22a7ec80fbfdc4d8ed796119c76bfac01e0a908 | cl.exe |
| SHA-256 | e1204ebbd8f15dbf5f2e41dddc5337e3182fc4daf75b05acc948b8b965480ca0 | cl.exe |
| SSDEEP | 3072:vv2ADi7yOcE/YMBSZ0fZX4kpK1OhJrDwM:vv2jeQ/flfZbKM | cl.exe |
| MD5 | 18e01dee14167c1cf8a58b6a648ee049 | win.bat |
| SHA-1 | fce0db6e66d227d3b82d4564446ede0c0fd7598c | win.bat |
| SHA-256 | ec4cd040fd14bff86f6f6e7ba357e5bcf150c455532800edf97782836e97f6d2 | win.bat |
| SSDEEP | 12:wbYVJ69/TsdLd6sdLd3mTDwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+EVTCuwfV+Et:wq69/kZxZ3mTDY9HY9HY9HY9HY9j | win.bat |
| MD5 | 0738242a521bdfe1f3ecc173f1726aa1 | goxml.jpg |
| SHA-1 | 683eaec2b3bb5436f00b2172e287dc95e2ff2266 | goxml.jpg |
| SHA-256 | 63dd02c371e84323c4fd9a161a75e0f525423219e8a6ec1b95dd9eda182af2c9 | goxml.jpg |
| SSDEEP | 12288:ME0p1RE70zxntT/ylTyaaSMn2fS+0M6puxKfJbDKrCxMe5fPSC2tmxVjpJT/n37p:MHyUt7yQaaPXS6pjar+MwrjpJ7VIbZg | goxml.jpg |
| MD5 | bbe983dba3bf319621b447618548b740 | GoXml.exe |
| SHA-1 | 5d117d8ef075f3f8ed1d4edcc0771a2a0886a376 | GoXml.exe |
| SHA-256 | f116acc6508843f59e59fb5a8d643370dce82f492a217764521f46a856cc4cb5 | GoXml.exe |
| SSDEEP | 768:+OFu8Q3w6QzfR5Jni6SQD7qSFDs6P93/q0XIc/UB5EPABWX:RFu8QAFzffJui79f13/AnB5EPAkX | GoXml.exe |
Provenance
Allegato ufficiale CISA · 2022-09-23T19:13:10Z
SHA-512: d8af448a49096b33ae821305f46b30e5d54aa2e4738851fae9220afe8a1a88b34af69374638ec8944bc0d326092506a780ae73802bf99b63ceee6ccf9aa6baa0
- Source
- CISA Cybersecurity Advisories
- Publishing entity
- CISA
- Entity type
- National authority
- Area
- North America · US
- Original language
- en · translation in preparation
- Publication
- 23/09/2022 14:00
- Sharing
- TLP:CLEAR
- MITRE ATT&CK
- T1003.001, T1021.001, T1021.002, T1027, T1059.003, T1068, T1071, T1112, T1136, T1140, T1190, T1486, T1561, T1567, T1590
- CVE
- CVE-2019-0604
- Classification
- Critical
- Stated country
- US
Affected products and versions
The collector will check NVD and the available official vendor advisories.
Action indicated by the source
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.