Drooid Logo
Back to story perspectives

Full Breakdown

Iran-Linked Cyber Attacks Target Middle Eastern Organizations

4/2/2026, 5:33:49 AM

Overview of the Cyber Attacks

Suspected Iran-linked threat actors have recently conducted password-spraying attacks against over 300 organizations, primarily targeting municipalities in Israel and the United Arab Emirates. According to Check Point Research, these attacks occurred in three distinct waves on March 3, March 13, and March 23, 2026. The attackers utilized multiple source IP addresses to compromise Microsoft 365 accounts, indicating a sophisticated approach to infiltrating sensitive environments.

Targeted Sectors and Implications

The majority of the attacks focused on Israel's municipal sector, which plays a crucial role in assessing and responding to missile-related damage. Other industries affected included technology, transportation and logistics, healthcare, and manufacturing. The correlation between the organizations targeted and cities that have been subjected to missile strikes suggests that the cyber operations may have been intended to support kinetic military actions and Bomb Damage Assessment (BDA) efforts.

Attack Methodology

The initial phase of the attack involved password spraying, where attackers attempted to gain access by exploiting weak passwords across numerous Microsoft accounts. This was executed using frequently changed Tor exit nodes, with the attackers masquerading their identity as Internet Explorer 10 users. Once valid credentials were identified, the attackers logged in from multiple VPN IP addresses geolocated in Israel, thereby circumventing geographical restrictions. This method allowed them to access personal emails and sensitive data from the compromised accounts.

Broader Context of Cyber Operations

The password-spraying incidents coincide with other cyber activities attributed to Iran-linked groups. Notably, Handala Hack, associated with Iran's intelligence agency, recently hacked the personal email account of FBI Director Kash Patel, claiming to have leaked sensitive information. This group has previously been involved in significant cyberattacks, including the destructive Stryker cyberattack. Following a brief disruption of their operations by the FBI, Handala Hack quickly resumed activities by launching new domains.

Official Statements & Responses

Check Point Research noted that the techniques observed in the password-spraying attacks bear similarities to those employed by the Gray Sandstorm group, which is known for its use of red-team tools and Tor exit nodes. The researchers emphasized the strategic nature of these attacks, suggesting they were likely designed to facilitate military objectives.

Criticism & Opposition

While the attacks have drawn attention to the vulnerabilities of critical infrastructure in the Middle East, there are concerns regarding the broader implications of such cyber operations. Critics argue that these activities could escalate tensions in the region and provoke retaliatory measures from affected nations.

Conflicting Reports & Gaps

There is a lack of clarity regarding the full extent of the damage caused by these attacks, as well as the specific identities of all targeted organizations. While Check Point Research has identified over 300 organizations in Israel and 25 in the UAE, the total number of affected entities in the U.S., Europe, and Saudi Arabia remains unspecified.

Verbatim Quotes

“Analysis of M365 logs suggest similarities to Gray Sandstorm, including the use of red-team tools to conduct these attacks via Tor exit nodes,” — Check Point Research

“This is just our beginning.” — Handala Hack