ROADSWEEP is a Windows ransomware family used in destructive and disruptive intrusion activity linked to Iranian state-aligned operations, most notably the 2022 attacks against Albania conducted under the HomeLand Justice banner. It encrypts files across accessible drives, including removable media, by enumerating directories and processing files in parallel with a separate thread per discovered drive. Encrypted files are renamed with a dedicated extension, and the malware drops ransom notes in targeted directories before or during encryption activity. ROADSWEEP uses RC4 to encrypt file contents in fixed-size blocks and overwrites the original data on disk rather than creating separate encrypted copies. It also preserves and restores original file timestamps, a behavior consistent with attempts to reduce obvious signs of tampering during execution.
The malware includes impact-maximizing and recovery-inhibition features typical of ransomware used in disruptive campaigns. It can disable System Restore and Volume Shadow Copies to hinder restoration efforts, and it supports identification of removable drives so that attached external storage can also be encrypted. ROADSWEEP additionally supports piping command output to another process and requires specific command-line arguments to execute correctly, indicating operator-controlled deployment rather than indiscriminate self-propagation. Samples associated with the campaign were digitally signed with a certificate issued to a telecommunications company, reflecting code-signing abuse for defense evasion and legitimacy. ROADSWEEP has been publicly associated with Iranian intrusion activity and has been discussed alongside other malware used in the same operational ecosystem, including CHIMNEYSWEEP and ZeroCleare, although those are distinct tools with different functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For each discovered drive, ROADSWEEP will initialize a new thread which is responsible for encrypting all files within that drive... The encryption process takes place by renaming the file with the “.lck” extension... ROADSWEEP will read in the data, encrypt the chunk using RC4, and then overwrite the file to disk.
During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.
The group first came to light in July 2022 in connection with destructive cyber attacks targeting Albania with a ransomware strain called ROADSWEEP...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples include 'contains an embedded, AES-encrypted resource named METADATA that contains configuration information for follow-on execution,' 'binary contains RC4 encrypted embedded scripts,' and 'initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.'
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
Following this, the aforementioned self-delete script is executed and the process exits.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU/RAM, BIOS, domain role, and other configuration data (e.g., “uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information.”).
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes malware and threat actors identifying, monitoring, or enumerating connected peripheral devices such as USB mass storage, Bluetooth devices, printers, smart card readers, cameras, Apple devices, VGA/display devices, and removable drives.
ROADSWEEP will initialize a new thread which is responsible for encrypting all files within that drive... if they do not the file is encrypted. The encryption process takes place by renaming the file with the '.lck' extension... ROADSWEEP will read in the data, encrypt the chunk using RC4, and then overwrite the file to disk.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
File-encrypting ransomware used to encrypt files on targeted systems during the HomeLand Justice operation.
Wiper malware that disables System Restore and Volume Shadow Copies.
Ransomware strain used in destructive attacks targeting Albania.
Backdoor that can pipe command output to another process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.