OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
ID: 66420fd0-aae4-5a96-b704-1150563fd127
STIX ID: report--66420fd0-aae4-5a96-b704-1150563fd127
Feed Name: Proofpoint Blog
**Proofpoint warned that multiple threat actors are weaponizing an Entra ID telemetry blind spot — "OAuth client ID spoofing" — which allows attackers to enumerate accounts and validate stolen credentials without generating successful sign-ins.** Two observed campaigns (UNK_pyreq2323 and UNK_OutFlareAZ) targeted millions of users across thousands of tenants using spoofed UUID client_ids via the ROPC flow and distributed infrastructure (AWS, Cloudflare), enabling large-scale, stealthy credential validation that can bypass application-scoped Conditional Access and typical sign-in detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
