No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
ID: 6acba207-73ef-5333-bf2f-682281a3761d
STIX ID: report--6acba207-73ef-5333-bf2f-682281a3761d
Feed Name: Huntress Blog
**Huntress observed a large-scale credential spray campaign (June 12–26) abusing the OAuth ROPC flow for Azure CLI, originating from IPv6 ranges tied to AS32167 (LSHIY LLC) and later shifting to other ASNs; the campaign generated over 81 million login attempts and resulted in at least 78 compromised Microsoft accounts across 64 organizations, exploiting Conditional Access/MFA misconfigurations and prompting recommendations to block ROPC, require MFA for all apps/users, and restrict Azure CLI access.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
