


























Check Point Research identified a password-spraying campaign conducted by an Iran-nexus threat actor, targeting cloud environments of government entities, municipalities, energy-sector organizations, and private-sector companies amid the ongoing conflict in the Middle East, primarily in Israel and the UAE.

Figure 1 – Iran-nexus Password Spraying Volume Over Time – March 2026
Unlike common brute-force attacks, password spraying targets multiple accounts with the same set of weak or commonly used passwords. The technique is based on the assumption that at least one user will have weak credentials. In this campaign, the attackers used multiple source IP addresses to target numerous accounts, making detection based on atomic indicators such as IPs more difficult.

Figure 2 – Example organization A – Failed sign in attempts for accounts in the tenant
This technique is popular among advanced threat actors and has been used in the past by multiple advanced groups. Iran-nexus actors such as Peach Sandstorm and Gray Sandstorm are known to use this method for initial access and exfiltration.
The campaign targets multiple sectors, with Israel’s municipal sector appearing to be the primary focus, both in the number of organizations targeted and in the volume of password-spraying attempts per organization.

Figure 3 – Top targeted sectors

Figure 4 – Attack Cycle
Check Point Research assesses with moderate confidence that the actor behind the M365 password-spray activity originates from Iran. This assessment is based on the activity profile’s alignment with Iranian interests, including targeting of Israeli local government entities and organizations in the satellite, aviation, energy, and maritime sectors.
Analysis of M365 logs suggest similarities to Gray Sandstorm, including the use of red-team tools to conduct these attacks via Tor exit nodes. The threat actor used commercial VPN nodes hosted at AS35758 (Rachamim Aviel Twito), which aligns with recent activity tied to Iran-nexus operations in the Middle east.
1. Detect password spray anomalies
Monitor sign-in logs to identify password spray behavior patterns, specifically multiple authentication failures across many distinct user accounts originating from the same source IP
2. Restrict access using geo-fencing and TOR IP block controls
Apply conditional access controls to restrict authentication by approved geographic locations (geo-fencing) and to block high-risk anonymization networks, including TOR exit nodes
3. Enforce MFA tenant-wide and strengthen credential hygiene
Enforce multi-factor authentication (MFA) across the tenant for all users, with stricter controls for privileged/admin roles. Additionally, implement strong credential hygiene, including regular password updates where required by policy and risk posture.
4. Enable audit logs for post-compromise investigation
Ensure audit logging is enabled and retained appropriately to investigate post-authentication activity following any suspected successful password spray.
Check Point Email Security provides an additional level of protection against Microsoft 365 focused attacks.
| Type | IOC |
| 185.191.204.202 | Windscribe VPN |
| 185.191.204.203 | Windscribe VPN |
| 169.150.227.3 | Nord VPN |
| 169.150.227.143 | Nord VPN |
| 169.150.227.146 | Nord VPN |
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。