news.mlab.sh
Threat intelligence
Threat actor

HomeLand Justice

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Iran
First seen
2022-01-01 00:00:00
Motivation
Sabotage and destruction
TLP
WHITE

(ClearSky) On September 23rd, 2022, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) jointly released an advisory analyzing a wave of cyber-attacks targeting the Government of Albania. The group, identifying as 'HomeLand Justice,' was attributed as an Iranian state threat actor. Homeland Justice launched its first campaign on July 15th, 2022, targeting Albanian e-government systems right before a planned conference of Iranian opposition group Mojahedin-e Khalq (Persian:مجاهدین ِ خلق), also known as MEK - a well-known Iranian group seeking to replace the current regime in Iran. The conference was cancelled following the attack. In September 2022, the actor launched a second campaign targeting Albanian border crossings. On December 24th, 2023, the actor publicized the current campaign, described in this blog, targeting Albanian infrastructure and government organizations. (Check Point) Void Manticore, linked to the Iranian Ministry of Intelligence and Security (MOIS), executes destructive wiping attacks alongside influence operations. Operating under various online personas, notably Homeland Justice for Albania and Karma for Israel, Void Manticore targets different regions with tailored attacks. Overlaps exist between Void Manticore and Scarred Manticore (OilRig, APT 34, Helix Kitten, Chrysene) targets, suggesting coordinated efforts and a systematic handoff of victims in MOIS. Utilizing five distinct methods, including custom wipers for Windows and Linux, Void Manticore disrupts operations through file deletion and shared drive manipulation.

Also known as

Banished KittenCOBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80Red SandstormStorm-0842Void Manticore

Vulnerabilities exploited

MITRE ATT&CK techniques

T1005 Data from Local SystemT1074 Data StagedT1113 Screen CaptureT1119 Automated CollectionT1123 Audio CaptureT1125 Video CaptureT1102 Web ServiceT1105 Ingress Tool TransferT1572 Protocol TunnelingT1110 Brute ForceT1082 System Information DiscoveryT1047 Windows Management InstrumentationT1072 Software Deployment ToolsT1651 Cloud Administration CommandT1041 Exfiltration Over C2 ChannelT1485 Data DestructionT1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1657 Financial TheftT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1566 PhishingT1098 Account ManipulationT1133 External Remote ServicesT1589 Gather Victim Identity InformationT1078 Valid AccountsT1679 Selective Exclusion

Coverage 3