Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s September 2022 investigation said a destructive cyberattack disrupted Albanian government systems on July 15, 2022, following a long-running intrusion and data theft campaign. It assessed Iranian government sponsorship with high confidence, while rating the narrower link between some access and exfiltration activity and the Iran-associated group EUROPIUM as moderate confidence.

What happened in the July 2022 attack?

Microsoft described a multistage operation that moved from gaining access to stealing information, deploying destructive malware and conducting information operations. The destructive phase disrupted government websites and public services. Microsoft tracked activity under four temporary DEV cluster labels; these are analytic designations, not proof that four distinct organizations or individuals carried out the operation.

Phase or activity Microsoft’s account
Initial access DEV-0861 was assessed as having gained access to a vulnerable SharePoint Server.
Data exfiltration DEV-0861 and DEV-0166 were associated with email theft during different periods.
Infrastructure probing DEV-0133 probed victim infrastructure.
Encryption and destruction DEV-0842 deployed ransomware and wiper malware.
Information operations Microsoft identified this as a campaign stage; its account did not assign it to one of the four DEV labels in the same way as the activities above.

In an April 2023 taxonomy update included in its investigation, Microsoft renamed the clusters Storm-0861, Storm-0166, Storm-0133 and Storm-0842, respectively. Microsoft’s incident analysis and naming update describes the stages and observed roles.

When did the intrusion begin?

The July 15, 2022 destructive attack came after months of access and email theft. Microsoft said DEV-0861 likely entered the network in May 2021 by exploiting CVE-2019-0604 on an unpatched SharePoint Server. CISA and the FBI later described the initial access as approximately 14 months before the destructive attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Period Reported activity Attribution
May 2021 Likely initial access through the unpatched SharePoint Server. Microsoft’s assessment: DEV-0861.
October 2021–January 2022 Email exfiltration. Microsoft attributed this activity to DEV-0861.
November 2021–May 2022 Email exfiltration. Microsoft attributed this activity to DEV-0166.
July 15, 2022 Destructive attack disrupted government websites and public services. Microsoft’s investigation.

The approximate 14-month interval is CISA/FBI’s characterization of this incident’s timeline, not a general measure of how long attacks of this kind take. The agencies’ joint advisory announcement also describes the long-running access, email exfiltration, ransomware and disk-wiper activity.

What did Microsoft conclude about Iran’s role?

Microsoft said the evidence it reviewed included attackers operating from Iran, tools previously used by Iranian actors, targeting consistent with Iranian interests, and ransomware and wiper artifacts linked to Iranian actors. Based on that evidence, it assessed Iranian government sponsorship with high confidence.

Microsoft’s assessment of a more specific connection was less certain: it found with moderate confidence that actors involved in initial access and exfiltration were linked to EUROPIUM, a group publicly associated with Iran’s Ministry of Intelligence and Security. Microsoft’s confidence in state sponsorship should not be read as conclusive identification of every operator or as proof that every tracked activity cluster was part of that group.

Microsoft interpreted the campaign’s messaging, timing and target selection as indicating likely retaliation for cyberattacks Iran perceived as involving Israel and the Iranian opposition group Mujahedin-e Khalq (MEK), which is based largely in Albania. That is Microsoft’s assessment of likely motive, not proof of the operators’ private intent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did the attack permanently wipe Albanian government data?

No irreversible data wiping was reported by Albania’s prime minister. On September 7, 2022, Edi Rama said the attack had failed to achieve its purpose, that systems were fully operational again and that there had been no irreversible wiping of data. His statement describes the reported recovery and outcome; it does not mean the disruption Microsoft documented did not occur. The Albanian government published Rama’s September 7 statement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did Albania respond, and what did CISA and the FBI advise?

Rama said Albania had concluded the attack was state-sponsored and orchestrated by Iran through four groups. He announced that Albania was severing diplomatic relations with Iran and that Iranian diplomatic, technical, administrative and security staff had 24 hours to leave the country.

The CISA/FBI announcement urged users and administrators to review the agencies’ recommended mitigations. Its incident account supports a practical takeaway: treat an attack that combines long-running access and data theft with ransomware and disk-wiper activity as a broader security incident, not just a ransomware event. The announcement does not establish that any particular commercial product would have prevented this attack.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.