• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
IT Infrastructure, Network Security, News

Microsoft: Threat Actor Conducting Password Sprays Against U.S., Israeli Defense Industry

Microsoft said it is tracking an alleged Iran-based threat actor that is targeting 250 organizations, including defense technology firms.

October 12, 2021 Zachary Comeau Leave a Comment

Microsoft January Patch Tuesday
wolterke/stock.adobe.com

Microsoft said it is tracking what it believes is an Iran-based threat actor that has been observed conducting “extensive password spraying” against more than 250 organizations, including U.S. and Israeli defense technology firms.

Other targets include points of entry in the Persian Gulf or global maritime transportation companies that do business in the Middle East. Since the targets are companies that support Iran’s geopolitical adversaries and are also frequently targeted by Iranian actors, Microsoft believes this activity is originating in Iran.

Microsoft has affixed the title DEV0-0343 to this threat activity cluster so it allows the company’s Threat Intelligence Center to track it as a unique set of information until they can reach high confidence about the origin or identity of the actor.

According to a security blog, less than 20 of the 250 Office 365 tenants have been successful compromised, but the group continues to evolve and refine their attacks.

Specifically, the attacks are targeting the U.S., Israeli and European Union defense companies that produce military-grade radars, drone technology, satellite systems and emergency response communication systems.

Because of those targets, Microsoft believes the activity supports Iran’s government tracking of adversary security services and maritime shipping in the Middle East to enhance their contingency plans, the company said.

“Gaining access to commercial satellite imagery and proprietary shipping plans and logs could help Iran compensate for its developing satellite program,” Microsoft said. “Given Iran’s past cyber and military attacks against shipping and maritime targets, Microsoft believes this activity increases the risk to companies in these sectors, and we encourage our customers in these industries and geographic regions to review the information shared in this blog to defend themselves from this threat.”

According to the blog, the password sprays emulate a Firefox browser via Ips hosted on a Tor proxy network, and are most active between Sunday and Thursday between 7:30 a.m. and 8:30 p.m. Iran Time.

Up to hundreds of accounts within a single organization are targeted, and an average of between 150 and 1,000 unique Tor proxy IP addresses are used in these attacks.

To defend against this attack and similar password sprays, Microsoft advises enabling multifactor authentication on all Office 365 accounts or using passowordless solutions like Microsoft Authenticator.

The company also suggests reviewing and enforcing recommended Exchange Online access policies and blocking all incoming traffic from anonymizing services where possible.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Cybersecurity, Microsoft

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Practical Design Guide for Office SpacesPractical Design Guide for Office Spaces

    Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-face time with co-workers. When designing the office spaces — and meeting spaces in particular — enabling that connection between co-workers is crucial. But introducing the right collaboration technology in meeting spaces can […]

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.