Activity timeline
UNK_OutFlareAZ appears in 3 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
- T1110 Brute Force — Credential Accessobserved in 2 of 3 tracked threats
- T1110.004 Credential Stuffing — Credential Accessobserved in 2 of 3 tracked threats
- T1201 Password Policy Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 3 tracked threats
- T1589 Gather Victim Identity Information — Reconnaissanceobserved in 2 of 3 tracked threats
- T1589.001 Credentials — Reconnaissanceobserved in 2 of 3 tracked threats
- T1589.002 Email Addresses — Reconnaissanceobserved in 2 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 1 of 3 tracked threats
- T1087 Account Discovery — Discoveryobserved in 1 of 3 tracked threats
- T1090 Proxy — Command and Controlobserved in 1 of 3 tracked threats
- T1090.002 External Proxy — Command and Controlobserved in 1 of 3 tracked threats
Tracked threats
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)HIGH
- OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 & UNK_OutFlareAZHIGH
- OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)HIGH