HomeSecurityIranian password-spraying campaign targets Israeli organizations

Iranian password-spraying campaign targets Israeli organizations

A threat actor linked to Iran is suspected of a password-spraying campaign targeting Microsoft 365 environments in Israel and the UAE.

password spraying

Check Point estimates that the activity is still ongoing and has taken place in three distinct waves of attacks: on March 3, March 13, and March 23, 2026.

“The campaign is primarily focused on Israel and the UAE, affecting more than 300 organizations in Israel and over 25 in the UAE ,” the Israeli cybersecurity firm said . “ Activity linked to the same actor was also observed against a limited number of targets in Europe, the United States, the United Kingdom and Saudi Arabia .”

See also: UAE: 75% of cyberattacks start with phishing emails

The campaign is estimated to target the cloud environments of government entities, municipalities, technology companies, transportation and energy organizations, and private sector companies in the region.

Password-spraying attacks against Microsoft 365 environments

Password-spraying is a form of brute-force where an attacker attempts to use a common password across multiple usernames in the same application. It is also considered a more effective way to discover weak credentials at scalewithout triggering rate-limiting defensive measures.

Iranian password-spraying campaign targets Israeli organizations

Check Point said this technique is often adopted by Iranian hacking groups. In the past, Peach Sandstorm and Gray Sandstorm (formerly DEV-0343) have used it to infiltrate target networks.

See also: European Commission Cloud Breach: 91GB of Data Leaked

The campaign essentially evolves in three phases: aggressive scanning or password-spraying carried out by Tor exit nodes, login process , and extraction of sensitive data.

“Analysis of M365 logs suggests similarities to Gray Sandstorm, including the use of red-team tools to conduct these attacks via Tor exit nodes,” Check Point said. “The threat actor used commercial VPN hosted on AS35758 (Rachamim Aviel Twito). This is consistent with recent Iranian activity in the Middle East.”

See also: Qilin and Warlock ransomware: Using vulnerable drivers to disable EDR

Iranian password-spraying campaign targets Israeli organizations

To address the threat, organizations are urged to monitor login logs for signs of password-spraying, implement conditional access controls to limit authentication to approved geographic locations, enforce multi-factor authentication (MFA) for all users, and enable audit logs for post-breach investigation .

source: thehackernews.com

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS