Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Iranian state-sponsored actors attacked Albanian government networks in July 2022, disrupting government websites and public services. But the sources do not identify a malware family called “No-Justice”: they describe a public-facing identity called HomeLand Justice and a wiper identified as cl.exe (Microsoft detection name DoS:Win64/WprJooblash) or as a version of ZeroCleare. HomeLand Justice claimed responsibility; that claim is distinct from investigators’ assessment of who conducted the operation.

What “No-Justice” means in accounts of the Albania attack

“No-Justice” is not an established malware name in the Microsoft, FBI/CISA or MITRE ATT&CK accounts of this incident. The name that appears in those records is HomeLand Justice, the identity used by the people who claimed responsibility. The destructive malware is described separately: Microsoft calls the wiper cl.exe and gives its detection name as DoS:Win64/WprJooblash; the FBI/CISA advisory describes a version of ZeroCleare.

That distinction matters. HomeLand Justice was a public persona, not a conclusively identified single operational group. Microsoft’s September 2022 investigation assessed that multiple Iranian government-sponsored actors handled different phases of the operation. MITRE ATT&CK’s maintained campaign record also associates the campaign with multiple Iran-nexus groups and labels. These are source-specific threat-intelligence mappings, not interchangeable names for one universally agreed group.

Who attacked Albania, and how strong is the Iran link?

Microsoft assessed with high confidence that Iranian government-sponsored actors carried out the destructive attack on July 15, 2022. The FBI and CISA described the operators as Iranian state cyber actors using the HomeLand Justice identity. These assessments concern the operation and its state sponsorship; they do not establish that the public-facing persona itself was a single, named government unit.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s analysis separates roles among several historic DEV-designated clusters: DEV-0842 deployed ransomware and the wiper; DEV-0861 was involved in initial access and exfiltration; DEV-0166 conducted additional exfiltration; and DEV-0133 probed infrastructure. Microsoft assessed with moderate confidence that actors involved in initial access and exfiltration were linked to EUROPIUM, which Microsoft later renamed Hazel Sandstorm and has publicly linked to Iran’s Ministry of Intelligence and Security. That moderate-confidence link applies to those actors, not as a replacement for or an upgrade of the separate high-confidence assessment about the destructive attack.

MITRE’s HomeLand Justice campaign record (C0038) also maps activity to labels including HEXANE and VOID MANTICORE. Those labels reflect MITRE’s campaign and group mappings, while Microsoft’s role breakdown uses its own cluster designations. Microsoft announced in April 2023 that its DEV identifiers map to Storm identifiers; the 2022 DEV labels are retained here to describe the analysis as it was reported.

How the attack unfolded

Period Reported activity
May 2021 Microsoft said the actors likely gained access by exploiting an unpatched SharePoint Server vulnerability. The FBI/CISA advisory and MITRE place initial access about 14 months before the destructive phase.
2021 to May 2022 Actors periodically accessed and exfiltrated email, according to the FBI/CISA advisory; Microsoft also observed email exfiltration during this period.
May–June 2022 The FBI/CISA investigation found lateral movement, reconnaissance and credential harvesting in Albanian government networks.
July 15, 2022 The destructive attack disrupted Albanian government websites and public services. HomeLand Justice claimed responsibility shortly afterward, according to the FBI/CISA advisory.
September 2022 The FBI/CISA advisory reported a further wave using similar tactics and malware. CERT-EU separately reported an incident on September 9 affecting Albanian state police computer systems.

The approximately 14-month interval is the time between initial access and the destructive phase, as described by the FBI/CISA advisory and MITRE’s campaign record. It is not the duration of the malware’s execution.

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

How the intruders got in and prepared the destructive phase

Microsoft said the initial access likely involved exploitation of CVE-2019-0604 on an unpatched SharePoint server. A misconfigured service account with local administrator membership helped fortify the actors’ access. They used web shells for persistence, then carried out credential theft, reconnaissance, defense evasion and lateral movement. Microsoft reported activity involving Mimikatz, Impacket and Remote Desktop; MITRE’s campaign record maps techniques including SharePoint exploitation, web shells, email collection, RDP/SMB lateral movement and credential dumping.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI/CISA account describes periodic access to email and exfiltration over the prolonged intrusion, followed by lateral movement and credential harvesting. The campaign therefore involved information theft before the destructive attack, rather than beginning and ending with a single burst of wiper activity.

Rank #2
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

What the ransomware and wiper did

The destructive phase combined ransomware with disk wiping. Microsoft identified the ransomware binary as GoXml.exe, the wiper as cl.exe (detected as DoS:Win64/WprJooblash) and a driver named rwdsk.sys. The FBI/CISA advisory says operators deployed a version of ZeroCleare after defenders began responding to the ransomware.

Microsoft found that the wiper used an EldoS RawDisk license-key value also associated with ZeroCleare. That is a technical link supporting the description of the malware as ZeroCleare-related; it does not establish that every observed sample was an identical build. The ransomware and wiper had different functions: ransomware was part of the attack’s destructive disruption, while wiping targeted data on disks rather than merely holding it for payment.

Rank #3
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about the damage and the September wave

Microsoft reported less than 10% total impact in the customer environment it investigated. That figure is limited to that environment; it is not an estimate of the proportion of Albanian government systems affected or a national damage measure. The sources cited here do not establish a broader, independently quantified statistic for the attack’s total impact across Albania.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The September 2022 activity belongs to the broader HomeLand Justice campaign record, but the available accounts describe it as a further wave rather than as proof that every later incident had the same target or operational details. The FBI/CISA advisory says the wave used similar tactics and malware, and CERT-EU records the September 9 effect on state police computer systems.

Sources and scope

  • Microsoft Threat Intelligence, “Microsoft investigates Iranian attacks against the Albanian government,” published September 8, 2022, with an April 2023 taxonomy update. This is the primary technical incident investigation cited for the attack chain, malware and attribution assessments.
  • FBI and CISA, “Joint Cybersecurity Advisory: Iranian State Actors Conduct Cyber Operations Against the Government of Albania,” September 21, 2022, reproduced by the American Hospital Association. It describes the investigation, prolonged access and September follow-on wave.
  • MITRE ATT&CK, “HomeLand Justice, Campaign C0038,” a maintained campaign record created August 6, 2024, version 1.1, last modified July 31, 2026. Its campaign and technique mappings are a maintained knowledge-base synthesis, not a contemporaneous 2022 incident report.
  • CERT-EU, “Cyber Brief – September 2022,” released October 3, 2022, for the September 9 state police incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.