hacker-news · Crawled Jul 14, 2026

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

1 IoCs
Read original article ↗

AI Summary

Two threat actor groups, UNK_pyreq2323 and UNK_OutFlareAZ, are exploiting OAuth client ID spoofing to validate stolen Microsoft Entra ID credentials without triggering successful sign-in events. By using spoofed but syntactically valid OAuth client IDs in ROPC authentication flows, attackers can enumerate valid accounts and passwords at scale while evading detection. The technique bypasses Conditional Access policies and leaves minimal telemetry, making it difficult for defenders to detect malicious activity.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Package Windows Live Custom Domains Details →