How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant
ID: df79a962-acd8-5e3e-a640-85cbcaea2179
STIX ID: report--df79a962-acd8-5e3e-a640-85cbcaea2179
Feed Name: Huntress Blog
Huntress observed a large-scale credential-spraying campaign (LSHIY) that targeted Azure CLI and leveraged the deprecated Resource Owner Password Credentials (ROPC) OAuth flow to bypass MFA and Conditional Access; the campaign generated a spike of over 81 million login attempts and 78 account compromises in a two-week window, originated from IPv6 BYOIP ranges (notably 2a0a:d683::/32 and later 2605:6400::/32, 2605:6404::/32) and moved between ISPs, and the report includes IoCs, analysis of the technique, and mitigations such as disabling ROPC, enforcing MFA and stricter Conditional Access policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
