US sent ‘hunt-forward’ team to Albania in wake of Iranian cyberattacks伊朗发动网络攻击后,美国向阿尔巴尼亚派遣了“前沿搜寻”小组。
Iran targeted Albanian networks in July and September, forcing offline key government services including the Total Information Management System.

WASHINGTON — U.S. cyber specialists spent three months in Albania working alongside forces there to identify network weaknesses and hacking tools following Iranian cyberattacks on government systems.
The so-called hunt-forward operation, a defensive measure taken at the invitation of foreign officials, was the first conducted in Albania, a smaller NATO ally. U.S. Cyber Command revealed the operation , handled by its Cyber National Mission Force, or CNMF, on March 23.
Army Maj. Gen. William Hartman, the commander of the mission force, in a statement said the operation brought CYBERCOM personnel “closer to adversary activity” while promoting international relationships.
Army Maj. Gen. William J. Hartman, commander of Cyber National Mission Force, foreground, is seen at ceremony in December 2022. (Provided/CYBERCOM)
“In an increasingly dynamic environment where malicious cyber actors attempt to exploit our networks, data, and critical infrastructure, we have a key asymmetric advantage that our adversaries don’t have: enduring partnerships , like this one with Albania,” he added.
Iran targeted Albanian networks in July and September, forcing offline key government services including the Total Information Management System, which tracks details of those entering and exiting the country.
The Biden administration condemned the digital belligerence and, ultimately, sanctioned Iran . The administration’s cybersecurity strategy identifies the Middle Eastern country as a burgeoning cyber power and a safe haven for ransomware abusers.
Nathaniel Fick, the U.S. ambassador at large for cyberspace and digital policy, in a statement Thursday said the U.S. remains committed “to working with Albania on securing its digital future, and ensuring that connectivity is a force for innovation, productivity, and empowerment.” He also called on other countries to hold Iran accountable for “its destructive cyberattacks.”
The CNMF has deployed more than three-dozen times to at least 22 countries — including Ukraine, ahead of Russia’s invasion — to bolster faraway networks and return with information that can be applied stateside.
Hunt-forward operations are part of CYBERCOM’s persistent engagement strategy, a means of being in constant contact with adversaries and ensuring proactive, not reactive, moves are made.
“When we are invited to hunt on a partner nations’ networks, we are able to find an adversary’s insidious activity in cyberspace and share with our partner to take action on,” Hartman said . “We can then impose costs on our adversaries by exposing their tools, tactics and procedures, and improve the cybersecurity posture of our partners and allies.”
Colin Demarest was a reporter at C4ISRNET, where he covered military networks, cyber and IT. Colin had previously covered the Department of Energy and its National Nuclear Security Administration — namely Cold War cleanup and nuclear weapons development — for a daily newspaper in South Carolina. Colin is also an award-winning photographer.
华盛顿——在伊朗对阿尔巴尼亚政府系统发动网络攻击后,美国网络专家在阿尔巴尼亚与当地部队并肩工作了三个月,以找出网络漏洞和黑客工具。
这项所谓的“前沿搜索行动”是应外国官员邀请而采取的防御措施,也是首次在北约较小的盟国阿尔巴尼亚进行。美国网络司令部于3月23日披露了这项由其网络国家任务部队(CNMF)负责执行的行动。
任务部队指挥官、陆军少将威廉·哈特曼在一份声明中表示,此次行动使网络司令部人员“更接近敌方活动”,同时促进了国际关系。
陆军少将威廉·J·哈特曼(William J. Hartman),网络国家任务部队司令,于2022年12月出席仪式。(图片由美国网络司令部提供)
“在网络环境日益动态变化,恶意网络行为者试图利用我们的网络、数据和关键基础设施时,我们拥有对手所不具备的关键不对称优势:持久的伙伴关系,例如与阿尔巴尼亚的这种伙伴关系,”他补充道。
伊朗在 7 月和 9 月对阿尔巴尼亚的网络进行了攻击,迫使包括全面信息管理系统在内的关键政府服务离线,该系统跟踪进出该国人员的详细信息。
拜登政府谴责了这种网络挑衅行为,并最终对伊朗实施了制裁。该政府的网络安全战略将这个中东国家视为一个新兴的网络强国,也是勒索软件滥用者的避风港。
美国负责网络空间和数字政策的无任所大使纳撒尼尔·菲克周四发表声明称,美国仍然致力于“与阿尔巴尼亚合作,确保其数字未来,并确保互联互通成为创新、生产力和赋能的动力”。他还呼吁其他国家追究伊朗“破坏性网络攻击”的责任。
CNMF 已向至少 22 个国家(包括俄罗斯入侵前的乌克兰)部署了 36 多次,以加强远距离网络并带回可在美国应用的信息。
前沿搜索行动是网络司令部持续接触战略的一部分,是与对手保持持续联系并确保采取主动而非被动行动的一种手段。
哈特曼表示:“当我们受邀在伙伴国家的网络上进行网络猎杀时,我们能够发现对手在网络空间的阴险活动,并与伙伴分享,以便他们采取行动。然后,我们可以通过揭露对手的工具、战术和程序来给他们造成损失,并提高伙伴和盟友的网络安全态势。”
科林·德马雷斯特曾是C4ISRNET的记者,负责报道军事网络、网络安全和信息技术方面的新闻。此前,他曾为南卡罗来纳州的一家日报报道美国能源部及其下属的国家核安全管理局,主要关注冷战后的清理工作和核武器研发。科林还是一位屡获殊荣的摄影师。