Iran-Linked Hackers Hit M365 Tenants in Middle East Password Spray Campaign
ID: 8564d4f2-6879-599f-8788-29d71c654ec6
STIX ID: report--8564d4f2-6879-599f-8788-29d71c654ec6
Feed Name: GBHackers
**Executive Summary:** Check Point Research observed an Iran-linked password-spraying campaign in March 2026 targeting Microsoft 365 tenants—primarily Israeli municipalities and several UAE organizations—aimed at intelligence collection and potentially supporting kinetic operations; attackers used password spraying, rotating VPN/Tor IPs (including Windscribe and NordVPN ranges), and an IE10 User-Agent to evade detection, impacting over 300 entities in Israel and prompting recommendations such as enforcing MFA, geo-fencing, blocking anonymization services, and retaining audit logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
