logo

Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts

ID: fd538f11-c792-5966-b62f-ec1258e9d922

STIX ID: report--fd538f11-c792-5966-b62f-ec1258e9d922

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-04-01

Date Updated: 2026-04-04

...
...

**Executive Summary:** In March 2026 the suspected Iranian APT group Gray Sandstorm conducted a multi-wave password spraying campaign against Microsoft 365 accounts at over 300 Israeli organizations and 25+ in the UAE, using weak credentials, rotating Tor exit nodes, and VPNs to evade detection and access sensitive information; the operation is ongoing and being monitored by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.