business / news / / The Hacker News
password-spraying campaign targeted Microsoft 365 environments in Israel and the U.A.E.
An Iran-linked actor conducted three password-spraying attack waves on Microsoft 365 in March 2026.
KEY POINTS
- Over 300 Israeli and 25 U.A.E. organizations were targeted, with some attacks extending to Europe and the U.S.
- Attackers used Tor exit nodes and commercial VPNs from AS35758, aligning with known Iranian tactics.
- Pay2Key ransomware resurfaced with upgraded evasion and anti-forensics, offering affiliates an 80% ransom share.
- A Linux variant of Pay2Key disables SELinux and AppArmor, enabling faster and more persistent encryption.
COMPANIES
Summarized by Newsio from The Hacker News. How we summarize →