Password spraying has remained a persistent intrusion technique against cloud identity platforms, with CISA warning that attackers commonly target single sign-on, federated authentication, and email services by trying a small set of weak passwords across many accounts to avoid lockouts. U.S. authorities linked some activity to Iranian actors tied to the Mabna Institute, while Microsoft later reported that Iran-linked DEV-0343 sprayed passwords across more than 250 Office 365 tenants, focusing on defense, GIS, maritime, and cargo organizations; fewer than 20 tenants were compromised, and accounts protected by multifactor authentication were largely resistant.
More recent reporting shows the tactic evolving at scale. SecurityScorecard described a botnet of more than 130,000 compromised devices conducting password spraying against Microsoft 365 by abusing Basic Authentication in non-interactive sign-ins, using credentials from infostealer logs and infrastructure tentatively linked to a likely Chinese-affiliated group. Detection content from Splunk also highlighted Okta ThreatInsight alerts for suspected password-spray activity, underscoring that identity providers continue to surface this behavior in telemetry. Across the reporting, defenders are urged to enforce MFA, disable legacy and Basic Authentication where possible, strengthen password policies, and monitor sign-in logs for repeated failures, unusual user agents, and distributed login attempts from many IP addresses.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection 'Okta ThreatInsight Suspected PasswordSpray Attack' from its content library in version 5.2.0 after updating detections to use new search logic and field names. The replacement detection was named 'Okta ThreatInsight Threat Detected.'
Based on server uptime analysis, SecurityScorecard assessed that a botnet of more than 130,000 compromised devices had likely been operating since December 2024. The botnet targeted Microsoft 365 accounts using non-interactive sign-ins with Basic Authentication and stolen credentials from infostealer logs.
Microsoft publicly reported that the Iran-linked DEV-0343 cluster had targeted more than 250 Office 365 tenants using password spraying and Tor-hosted infrastructure. The company said multifactor authentication protected Office 365 accounts from these attempts and published mitigation guidance.
Beginning in late July 2021, DEV-0343 conducted extensive password spraying against more than 250 Office 365 tenants, primarily targeting U.S. and Israeli defense technology firms, GIS organizations, Persian Gulf ports of entry, and maritime transportation companies. Microsoft said fewer than 20 tenants were successfully compromised.
Microsoft Threat Intelligence Center first observed and began tracking the DEV-0343 activity cluster in late July 2021. The cluster was later assessed as Iran-linked and associated with large-scale password spraying.
DHS and the FBI jointly released an alert describing password spraying as an increasingly common brute-force technique affecting organizations in the United States and abroad. The alert linked the activity pattern to FBI investigations involving Iranian nationals tied to the Mabna Institute, while noting the techniques were not unique to that group.
Microsoft published best practices for defending Azure AD and ADFS environments against password spray attacks. The reference identifies this as a defensive guidance publication rather than a specific intrusion disclosure.
In February 2018, the Department of Justice for the Southern District of New York indicted nine Iranian nationals associated with the Mabna Institute for computer intrusion offenses related to the password-spraying activity described in the alert.
SecurityScorecard reported a botnet of over 130,000 compromised devices conducting password spraying against Microsoft 365 accounts by abusing Basic Authentication in non-interactive sign-ins. The company tentatively attributed the activity to a likely Chinese-affiliated group and identified six suspected C2 servers.
SecurityScorecard said its initial investigation began after failed sign-in attempts were observed in the non-interactive sign-in logs of a Microsoft 365 tenant. The investigation led to identification of a large password-spraying botnet and six suspected command-and-control servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcemicrosoft.com
Open sourceired.team
Open sourceus-cert.cisa.gov
Open sourcemicrosoft.com
Open sourceus-cert.gov
Open sourceus-cert.gov
Open sourcesecurityscorecard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.