logo

No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack

ID: 6acba207-73ef-5333-bf2f-682281a3761d

STIX ID: report--6acba207-73ef-5333-bf2f-682281a3761d

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-06-30

Date Updated: 2026-07-19

...
...

**Huntress observed a large-scale credential spray campaign (June 12–26) abusing the OAuth ROPC flow for Azure CLI, originating from IPv6 ranges tied to AS32167 (LSHIY LLC) and later shifting to other ASNs; the campaign generated over 81 million login attempts and resulted in at least 78 compromised Microsoft accounts across 64 organizations, exploiting Conditional Access/MFA misconfigurations and prompting recommendations to block ROPC, require MFA for all apps/users, and restrict Azure CLI access.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.