An Iran-linked threat actor conducted a password-spraying campaign against Microsoft 365 tenants, hitting more than 300 organizations in Israel and over 25 in the United Arab Emirates, with additional targeting in Europe, the United States, the United Kingdom, and Saudi Arabia. Check Point said the activity unfolded in three waves on March 3, 13, and 23 and primarily targeted municipalities, government bodies, energy and transportation organizations, technology firms, and other private-sector cloud environments. The attackers relied on weak passwords and exposed cloud accounts rather than malware or software exploits, using rotating Tor exit nodes and a spoofed Internet Explorer 10 on Windows 7 user agent during reconnaissance before shifting successful logins to commercial VPN infrastructure, including services associated with Windscribe and NordVPN, geolocated in Israel.
Researchers said the intrusions led to access to email, documents, administrative tools, and in some cases mailbox data exfiltration. Check Point assessed the activity with moderate confidence as Iran-linked and noted similarities to Gray Sandstorm, while also tying parts of the infrastructure to AS35758, which has been associated with recent Iran-nexus operations. Israeli municipalities were identified as a primary focus, and the campaign may have supported broader operational objectives such as damage assessment tied to regional military activity. Defenders were urged to review sign-in logs for distributed authentication failures, enforce tenant-wide MFA, strengthen password policies, apply location-based access controls, block Tor where feasible, and retain audit logs for investigation.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
By April 2026, Check Point publicly reported the March password-spraying campaign and said it affected more than 300 organizations in Israel and over 25 in the UAE. The company assessed with moderate confidence that the activity was linked to an Iran-origin actor, noting similarities to Gray Sandstorm and infrastructure associated with recent Iran-nexus operations.
On March 23, 2026, a third wave of the campaign was recorded, continuing attacks against organizations in Israel and the UAE with limited additional targeting in Europe, the United States, the United Kingdom, and Saudi Arabia. After successful authentication, the actor shifted from Tor-based reconnaissance to commercial VPN infrastructure and conducted mailbox data exfiltration.
On March 13, 2026, researchers observed a second wave in the same password-spraying campaign. The activity continued to focus on Microsoft 365 tenants, especially municipalities, government entities, energy organizations, and private companies in Israel and the UAE.
On March 3, 2026, an Iran-linked threat actor launched the first observed wave of password-spraying attacks against Microsoft 365 environments. The campaign primarily targeted organizations in Israel and the United Arab Emirates, using Tor exit nodes to attempt logins against exposed cloud accounts.
In late February 2026, the Iranian ransomware group Pay2Key targeted a U.S. healthcare organization using an updated ransomware variant with stronger evasion and anti-forensics features. Researchers said the intrusion involved a legitimate remote access tool, defense disabling, recovery inhibition, ransomware deployment, and log clearing, with no data exfiltration observed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.