Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
ID: 4aa06b5b-caf7-5944-a07e-1e1674f95254
STIX ID: report--4aa06b5b-caf7-5944-a07e-1e1674f95254
Feed Name: HackRead
- Researchers observed multiple large campaigns using spoofed OAuth client IDs against Microsoft Entra ID to enumerate and validate credentials by interpreting specific AADSTS error codes (e.g., AADSTS50126, AADSTS50034, AADSTS700016). Two campaigns (UNK_pyreq2323 and UNK_OutFlareAZ) targeted millions of accounts across thousands of tenants using AWS and Cloudflare infrastructure, varied user agents and request patterns, and generated hundreds of thousands to millions of spoofed client IDs to evade application-level detections and cause significant account lockouts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
