During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.5
campaign
HomeLand Justice C0038
- First seen
- May 2021
- Last seen
- September 2022
- Created
- 6 August 2024
- Last modified
- 31 July 2026
HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for HomeLand Justice was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including HEXANE who probed victim infrastructure.[1][2][3] A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.[3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0038
During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.67
During HomeLand Justice, threat actors used SMB for lateral movement.89
During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.1011
During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.12
During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.1314
Standing C0038
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
70th percentile · 70% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
96th percentile · 96% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
89th percentile · 89% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
93rd percentile · 93% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0038
1525 distinct rules cover the 25 techniques recorded for this campaign. The 1652 technique-to-rule mappings resolve to 1525 distinct rules, because one rule can cover several techniques. 1013 Sigma · 512 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org