logo

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

ID: df79a962-acd8-5e3e-a640-85cbcaea2179

STIX ID: report--df79a962-acd8-5e3e-a640-85cbcaea2179

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-08-19

...
...

Huntress observed a large-scale credential-spraying campaign (LSHIY) that targeted Azure CLI and leveraged the deprecated Resource Owner Password Credentials (ROPC) OAuth flow to bypass MFA and Conditional Access; the campaign generated a spike of over 81 million login attempts and 78 account compromises in a two-week window, originated from IPv6 BYOIP ranges (notably 2a0a:d683::/32 and later 2605:6400::/32, 2605:6404::/32) and moved between ISPs, and the report includes IoCs, analysis of the technique, and mitigations such as disabling ROPC, enforcing MFA and stricter Conditional Access policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.