Attribution
Online persona, not an independent intrusion set. Operated by Void Manticore (Iran, MOIS-affiliated) - High confidence: Check Point Research says Void Manticore operates Homeland Justice 'for attacks in Albania' and describes it as 'a persona the group continues to use in operations targeting Albania'; MITRE ATT&CK lists it under VOID MANTICORE (G1055) and as campaign C0038; Microsoft found that DEV-0842 (now Storm-0842, i.e. Void Manticore) 'deployed the ransomware and wiper malware' in the July 2022 attack the persona claimed; and the US DOJ describes Justicehomeland[.]org as an official website of 'a shell hacktivist entity used by MOIS'. Initial access for that attack came from a separate cluster that Microsoft links, at moderate confidence, to EUROPIUM. Claims published under the persona are the operator's own assertions unless independently corroborated.
Origin
Iran (operator assessed)
First seen
2022 (website and social media profiles created in June 2022, per CISA/FBI)
Last active
2026 (claimed intrusion into the Albanian parliament's email, March 2026 - self-claim; Albanian authorities had not publicly attributed it)
Motivation
Destructive and psychological operations against Albania - wiper attacks and hack-and-leak, with anti-MEK messaging (CISA/FBI)
Attribution confidence
high
Why it mattersState-sponsored / APT actor, high confidence (Government sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.