Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts
ID: fd538f11-c792-5966-b62f-ec1258e9d922
STIX ID: report--fd538f11-c792-5966-b62f-ec1258e9d922
Feed Name: ThreatCluster
Threat Score
**Executive Summary:** In March 2026 the suspected Iranian APT group Gray Sandstorm conducted a multi-wave password spraying campaign against Microsoft 365 accounts at over 300 Israeli organizations and 25+ in the UAE, using weak credentials, rotating Tor exit nodes, and VPNs to evade detection and access sensitive information; the operation is ongoing and being monitored by researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
