An Iran-linked threat actor is suspected of running a password-spraying campaign against Microsoft 365 environments in Israel and the United Arab Emirates, with more than 300 organizations in Israel and over 25 in the U.A.E. affected across three attack waves in March 2026.
KEY FACTS
- Targeting The campaign focused on government, municipal, technology, transportation, energy and private-sector organizations.
- Timeline Attack waves were observed on March 3, March 13 and March 23, 2026.
- Method The activity used password spraying against Microsoft 365 logins, often through Tor exit nodes and commercial VPNs.
- Impact The observed behavior included login attempts and possible mailbox data theft.
In a technical analysis by Check Point, the company said the same actor was also seen against a limited number of targets in Europe, the United States, the United Kingdom and Saudi Arabia. The report said the campaign appeared to unfold in three phases, starting with scanning and password spraying, then login attempts, then exfiltration of sensitive data such as mailbox content.
Check Point said the technique resembles tactics used by Iranian groups in past intrusions. The report also linked the activity to red-team tools and to commercial VPN nodes hosted at AS35758, which it said matched recent Iran-nexus operations in the Middle East.
The disclosure said organizations should watch sign-in logs for signs of password spraying, enforce multi-factor authentication, apply conditional access controls tied to approved locations and keep audit logs enabled for later review. It did not say whether the campaign had been contained.
Separately, a U.S. healthcare organization was targeted in late February 2026 by Pay2Key, an Iranian ransomware gang with ties to the Fox Kitten group. The attack used a legitimate remote access tool, credential harvesting, defenses tampering and log clearing, but no data exfiltration was reported.
WHY IT MATTERS
Password spraying remains a low-noise way to test weak credentials across many accounts, especially in cloud services. The Middle East focus and the related ransomware activity show how account access and extortion operations can overlap in regional cyber conflict.

