No-Justice is a wiper malware used in Iran-linked destructive operations, most notably against Albanian organizations. Reporting attributes its use to the threat actor Homeland Justice, an Iranian psychological operation group assessed as likely state-sponsored, and broader reporting links related Albania intrusions to Iranian activity clusters associated with MOIS. No-Justice was used in a December wave of attacks targeting the Albanian parliament, telecom providers ONE Albania and Eagle Mobile, and the national carrier Air Albania; subsequent intrusions in Albania and Israel were also reported to leverage No-Justice. The malware targets Windows systems and can crash the operating system in a way that prevents it from rebooting. It requires administrator privileges to wipe data and was reported to use a valid digital signature to appear legitimate. ClearSky reported that operators used a PowerShell script to copy and propagate the wiper across organizational networks before activation. The operation likely also involved publicly available tools including Plink, RevSocks, and the Windows 2000 resource kit, for functions such as network communication, possible exfiltration or command and control, reconnaissance, and persistent remote access. The attackers claimed data theft, but that was not confirmed. The campaign was described as possible retaliation for Albania sheltering MEK members in Durrës, and the attackers named it "Destroy Durres Military Camp." The full extent of damage was unclear at the time of reporting; local media said that during the parliament attack, the attackers attempted to interfere with infrastructure and delete data but were unsuccessful.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...with subsequent intrusions in Albania and Israel leveraging new wipers dubbed No-Justice...
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper used in subsequent intrusions in Albania and Israel.
Wiper malware used in attacks on Albanian organizations; it can crash Windows so it cannot be rebooted and requires administrator privileges to wipe data. It was observed with a propagation PowerShell script and was signed with a valid digital signature to appear legitimate.
A wiper malware referenced in relation to Iranian APT activity targeting Albania.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.