Skip to content
Deep Analysis4 min read

Iran: Missiles on Cities, Password Spraying on Municipalities — How Tehran Synchronizes Kinetic and Cyber Warfare

7 April 2026|AEGIDA Research Team

On March 31, 2026, Check Point Research published an analysis that redefines the concept of hybrid warfare. A password-spraying campaign by an Iranian actor hit over 300 Israeli organizations and more than 25 in the UAE in three distinct waves — March 3, 13, and 23. But the data that transforms this from a "normal" cyber attack into an integrated warfare case study is different: Check Point identified a correlation between the cities targeted by password spraying and those hit by Iranian missiles during the same period. Municipalities — the entities responsible for emergency response to physical bombing damage — were the primary cyber target.

Three Waves, One Objective: Blinding Emergency Response

The campaign unfolded in three waves at regular ten-day intervals. In each phase, the primary target was municipalities — the local administrations managing essential services: civil protection, fire departments, local healthcare, water distribution, and shelter management. The operational logic is devastating in its simplicity: when a missile hits a city, the first responders are municipal services. If those services are paralyzed by a simultaneous cyber attack, emergency response capability collapses.

Check Point identified a direct correlation between cities targeted by the password-spraying campaign and those hit by Iranian missiles during March 2026. This is not opportunistic — it is an integrated military operation where the cyber domain is synchronized with the kinetic domain to amplify overall destructive effect.

Technical Anatomy: Scan, Infiltrate, Exfiltrate

In the Scan phase, attackers conducted intensive password spraying against hundreds of organizations, rotating through Tor exit nodes. The User-Agent was "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" — simulating Internet Explorer 10 on Windows 7, a deliberately dated signature blending with legacy traffic still present in government networks.

In the Infiltrate phase, once valid credentials were found, attackers switched from Tor to commercial VPN providers — Windscribe (185.191.204.x) and NordVPN (169.150.227.x) — geolocated in Israel to bypass M365 geographic restrictions. The switch from Tor to Israeli-geolocated commercial VPNs is tactically sophisticated: logins appear from legitimate Israeli IPs, defeating geo-based access controls.

In the Exfiltrate phase, valid credentials enabled access to personal emails, internal documents, emergency plans, and sensitive data. For municipalities, this means potential access to evacuation plans, shelter lists, and bombing response protocols — exactly the intelligence a military adversary would want during active conflict.

Attribution: Gray Sandstorm and the Iranian Ecosystem

Check Point attributed the campaign to an Iranian actor with moderate confidence. The Unit 42 report (March 26, 2026) documents massive Iranian cyber escalation after late-February military operations, with at least 12 pro-Iran hacktivist groups active: Handala Hack (MOIS-linked), APT Iran, Cyber Islamic Resistance, Dark Storm Team, and others. Unit 42 identified 7,381 phishing URLs across 1,881 hostnames linked to the Iranian campaign.

The CISA-FBI-DC3-NSA advisory explicitly warns: "U.S. critical infrastructure organizations should remain vigilant for potential targeted cyber activity by Iranian-affiliated cyber actors." The password-spraying campaign against Israel and UAE is the operational proving ground — the same TTPs are being adapted for Western targets.

The European Target: Not Just the Middle East

Check Point documented activity by the same actor against a limited number of targets in Europe, the United States, the United Kingdom, and Saudi Arabia. The Iranian cyber ecosystem has repeatedly demonstrated the capability to strike Western targets: the 2024 joint CISA advisory (AA24-290A) already documented Iranian brute-force operations against U.S. critical infrastructure in healthcare, government, IT, engineering, and energy sectors. The Handala attack on Stryker — 80,000 devices wiped, 50 TB exfiltrated — confirms Iranian actors have both will and capability to hit critical Western supply chains.

The Integrated Hybrid Warfare Paradigm

The synchronization between missiles and password spraying represents a qualitative evolution in hybrid warfare doctrine. Until now, cyber and kinetic operations were considered complementary but separate: Russia used cyberattacks before the Ukraine invasion (Viasat, February 2022) as preparation, not simultaneous integrated operations. Iran went further: cyber doesn't prepare the physical attack — it amplifies it in real time.

The implications for NATO and Europe are immediate. If an adversary can simultaneously strike a city's physical infrastructure and digital emergency response systems, urban resilience — defined by NATO Treaty Article 3 as a prerequisite for collective defense — is compromised. European civil protection plans, built on the assumption that communication systems function during emergencies, must be recalibrated for a scenario where those systems are the first target.

IOCs and Technical Indicators

  • Windscribe VPN IPs: 185.191.204.202, 185.191.204.203
  • NordVPN IPs: 169.150.227.3, 169.150.227.143, 169.150.227.146
  • User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)
  • Target: Microsoft 365 / Entra ID environments
  • Pattern: multiple failed authentications across distinct accounts from same IP in narrow time windows
  • VPN infrastructure on AS35758 (Rachamim Aviel Twito)

Operational Recommendations

  1. 1.M365 access log monitoring: look for multiple failed authentications across different accounts from the same IP, especially from Tor nodes or commercial VPNs.
  2. 2.Conditional Access with geo-fencing: block Tor IP access and require MFA for commercial VPN access. Note: attackers use locally-geolocated VPNs to bypass standard geo-fencing.
  3. 3.MFA on all accounts: multi-factor authentication blocks 99% of password-spraying attacks. Use hardware tokens or authenticator apps, not SMS.
  4. 4.Weak password audit: scan for common passwords and force changes on any account using top-1000 most common passwords.
  5. 5.IOC threat hunting: check M365 logs for access from Check Point-identified IP ranges and Internet Explorer 10 User-Agent.
  6. 6.Offline continuity plans: emergency response systems must function without cloud access. Back up evacuation plans, shelter lists, and emergency protocols on offline physical media.
  7. 7.Critical communications encryption: in a hybrid warfare scenario, emergency service communications must be end-to-end encrypted on cloud-independent channels.

Conclusion: The New Doctrine of Simultaneous Warfare

The Iranian campaign of March 2026 marks a before and after in hybrid warfare history. For the first time in a documented manner, a state synchronized missile attacks with password-spraying operations against the same target cities, specifically targeting municipal emergency response systems. For every European city, every municipality, every essential service operator, the question is: if M365 civil protection systems were inaccessible during a real emergency tomorrow, does a Plan B exist?

Primary sources: Check Point Research (official blog, March 31, 2026), Unit 42/Palo Alto Networks (Threat Brief, updated March 26, 2026), Cybersecurity Dive (April 1, 2026), The Hacker News (April 6, 2026), CISA-FBI-DC3-NSA (advisory AA24-290A), The Register (March 31, 2026). IOCs available in the Check Point Research report.