# UNK_OutFlareAZ

> As of 2026-09-13, UNK_OutFlareAZ is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning cloud, vulnerability, threat intel. ATT&CK coverage spans 33 techniques across 11 tactics in 3 of 3 tracked threats. Most-observed techniques: T1036 (Masquerading), T1036.005 (Match Legitimate Resource Name or Location), T1078.004 (Cloud Accounts).

- **Tracked threats:** 3
- **Categories:** CLOUD, VULNERABILITY, THREAT_INTEL
- **As of:** 2026-09-13

## ATT&CK techniques observed

33 techniques observed across 3 of 3 tracked threats. Tactics: Resource Development (6), Reconnaissance (5), Credential Access (4), Defense Impairment (4), Discovery (3), Initial Access (3).

- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1078.004](https://intel.threadlinqs.com/technique/T1078.004) Cloud Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1087.004](https://intel.threadlinqs.com/technique/T1087.004) Cloud Account — Discovery — observed in 2 of 3 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 2 of 3 tracked threats
- [T1110.004](https://intel.threadlinqs.com/technique/T1110.004) Credential Stuffing — Credential Access — observed in 2 of 3 tracked threats
- [T1201](https://attack.mitre.org/techniques/T1201/) Password Policy Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1583.006](https://intel.threadlinqs.com/technique/T1583.006) Acquire Infrastructure: Web Services — Resource Development — observed in 2 of 3 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 2 of 3 tracked threats
- [T1589.001](https://intel.threadlinqs.com/technique/T1589.001) Credentials — Reconnaissance — observed in 2 of 3 tracked threats
- [T1589.002](https://intel.threadlinqs.com/technique/T1589.002) Email Addresses — Reconnaissance — observed in 2 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 1 of 3 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 1 of 3 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 1 of 3 tracked threats
- [T1090.002](https://intel.threadlinqs.com/technique/T1090.002) External Proxy — Command and Control — observed in 1 of 3 tracked threats

## Tracked threats

- [OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)](https://intel.threadlinqs.com/threat/TL-2026-2476) — HIGH
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 & UNK_OutFlareAZ](https://intel.threadlinqs.com/threat/TL-2026-1342) — HIGH
- [OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)](https://intel.threadlinqs.com/threat/TL-2026-1321) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNK_OutFlareAZ
