Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
ID: 5ce10d3a-011a-5f50-93a7-d4133a3bc210
STIX ID: report--5ce10d3a-011a-5f50-93a7-d4133a3bc210
Feed Name: The Hacker News
An Iran-nexus threat actor conducted three waves of password-spraying attacks in March 2026 targeting Microsoft 365 cloud environments—primarily in Israel (300+ organizations) and the UAE (25+ organizations)—using Tor exit nodes and commercial VPN infrastructure (AS35758) to attempt logins and exfiltrate mailbox data; concurrently, Iranian-linked ransomware operations (Pay2Key and BQTLock/Sicarii-related activity) have re-emerged with improved evasion, a Linux variant requiring root and ChaCha20 encryption, and tactics to disable defenses and clear logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
