hacker-news · Crawled Jul 14, 2026
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
1 IoCs
Read original article ↗
AI Summary
Two threat actor groups, UNK_pyreq2323 and UNK_OutFlareAZ, are exploiting OAuth client ID spoofing to validate stolen Microsoft Entra ID credentials without triggering successful sign-in events. By using spoofed but syntactically valid OAuth client IDs in ROPC authentication flows, attackers can enumerate valid accounts and passwords at scale while evading detection. The technique bypasses Conditional Access policies and leaves minimal telemetry, making it difficult for defenders to detect malicious activity.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Package | Windows Live Custom Domains | Details → |