More than 300 organizations in Israel, over 25 others in the United Arab Emirates, and a limited number of entities in the U.S., Saudi Arabia, and Europe have had their Microsoft 365 environments targeted by Iran-nexus hackers as part of a password spraying campaign that has been underway since early March, The Register reports.Intrusions believed to assist in bombing damage assessment initiatives and kinetic operations were conducted in three waves, commencing with the widespread scanning of Microsoft accounts with weak passwords via Tor exit nodes, which is a technique commonly employed by Iranian state-backed threat operation Gray Sandstorm, according to a Check Point Research analysis. Attackers then leveraged various VPN IP addresses geolocated in Israel to log in using the stolen valid credentials and compromise emails and other sensitive information.Such findings come as Iran-linked hacktivist operation Handala Hack leaked FBI Director Kash Patel's personal emails and breached leading U.S. medical device firm Stryker.
Threat Intelligence, Identity

Widespread Microsoft 365 account compromise sought by Iran-linked hackers

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
