Cyber Attacks, Albanian Govt Amends Deal with Microsoft

Albanian government has approved some changes in the agreement between the Council of Ministers of the Republic of Albania and the company "Microsoft Corporation". 

Through a Normative Act, the Council of Ministers has decided to amend the agreement with "Microsoft" for cyber security, expanding the areas of engagement of the American giant. 

Meanwhile, the decision states that the total fund for such a thing will be 2.4 billion ALL or about 20 million euros. What did "Microsoft" find from the investigation? "Microsoft" has devoted a detailed report to Iran's cyber attack, which Albania faced on July 15, 2020. 

Hacking of Albania's systems was due to an out-of-date server, returning the hackers to a gateway in May. 

“Hackers put themselves in strong positions in July 2021, undoing the configuration of the service accounts and turning into local administrators of the group. They then, in the time period October 2021 to January 2022, stole electronic communications through email", as ascertained. 

The most disturbing finding of "Microsoft" concerns the time when Iranian hackers were able to penetrate the Albanian government electronic systems for the first time. The hacker group, which we estimate to be linked to Iran, in all likelihood gained access to the Albanian government network in May 2021, using a vulnerability in the "SharePoint" server, which was not updated. The server is "administrata.al". 

"Microsoft" has found that Iran's attack on Albanian servers took place in four stages. Initially, "malware" viruses were installed on the Albanian servers for erasing data. 

The second step, access to unauthorized data transfer. Third step was the theft of data and the fourth step was the exploration and examination of the victim's infrastructure, in the specific case of ANA.