Campaign · all campaigns
HomeLand JusticeC0038 state
🇮🇷 IR
aka HomeLand Justice
Last updated: 2026-08-20
About this actor
[HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for [HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including [HEXANE](https://attack.mitre.org/groups/G1001) who probed victim infrastructure.(Citation: Mandiant ROADSWEEP August 2022)(Citation: Microsoft Albanian Government Attacks September 2022)(Citation: CISA Iran Albanian Attacks September 2022) A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.(Citation: CISA Iran Albanian Attacks September 2022)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 36 ATT&CK techniques on file.
- Named victims
- 1 extracted from reporting · 1 from the curated floor.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1041Exfiltration Over C2 Channel ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1078Valid Accounts ↗T1078.001Default Accounts ↗T1087Account Discovery ↗T1087.003Email Account ↗T1098Account Manipulation ↗T1098.002Additional Email Delegate Permissions ↗T1105Ingress Tool Transfer ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1134Access Token Manipulation ↗T1134.001Token Impersonation/Theft ↗T1190Exploit Public-Facing Application ↗T1486Data Encrypted for Impact ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1561Disk Wipe ↗T1561.002Disk Structure Wipe ↗T1570Lateral Tool Transfer ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.003Code Signing Certificates ↗T1685Disable or Modify Tools ↗T1685.001Disable or Modify Windows Event Log ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 30 / 36 | 83% |
AC-3 | 28 / 36 | 78% |
CM-6 | 27 / 36 | 75% |
AC-6 | 26 / 36 | 72% |
AC-2 | 24 / 36 | 67% |
CM-2 | 23 / 36 | 64% |
AC-5 | 19 / 36 | 53% |
IA-2 | 19 / 36 | 53% |
CM-7 | 18 / 36 | 50% |
SI-3 | 18 / 36 | 50% |
CM-5 | 17 / 36 | 47% |
SI-7 | 17 / 36 | 47% |
CA-7 | 15 / 36 | 42% |
AC-4 | 12 / 36 | 33% |
RA-5 | 10 / 36 | 28% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- INC Ransom 0.32
- 2016 Ukraine Electric Power Attack 0.31
- Agrius 0.29
- C0018 0.29
- Blue Mockingbird 0.27
Same nation-state
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- OilRig 1.00
- CopyKittens 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00