Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0038
MITRE ATT&CK Campaign · 2021–2022

HomeLand Justice (C0038)

ShareXLinkedInRedditHN

[HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for [HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including [HEXANE](https://attack.mitre.org/groups/G1001) who probed victim infrastructure.(Citation: Mandiant ROADSWEEP August 2022)(Citation: Microsoft Albanian Government Attacks September 2022)(Citation: CISA Iran Albanian Attacks September 2022) A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.(Citation: CISA Iran Albanian Attacks September 2022)

▪Attributed groups (1)

G1055VOID MANTICORE

▪Techniques used (25)

T1486Data Encrypted for ImpactT1561.002Disk Structure WipeT1041Exfiltration Over C2 ChannelT1046Network Service DiscoveryT1098.002Additional Email Delegate PermissionsT1134.001Token Impersonation/TheftT1078.001Default AccountsT1114.002Remote Email CollectionT1190Exploit Public-Facing ApplicationT1021.001Remote Desktop ProtocolT1588.003Code Signing CertificatesT1685Disable or Modify ToolsT1003.001LSASS MemoryT1059.003Windows Command ShellT1036.005Match Legitimate Resource Name or LocationT1505.003Web ShellT1021.002SMB/Windows Admin SharesT1570Lateral Tool TransferT1047Windows Management InstrumentationT1059.001PowerShellT1105Ingress Tool TransferT1087.003Email AccountT1588.002ToolT1685.001Disable or Modify Windows Event LogT1078Valid Accounts

▪Software used (7)

S0357ImpackettoolS1149CHIMNEYSWEEPmalwareS1151ZeroClearemalwareS0002MimikatztoolS0095ftptoolS1150ROADSWEEPmalwareS0364RawDisktool
C0038on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.