Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-07

UNK_pyreq2323

Also known as:UNK_OutFlareAZ

As of 2026-07-14, UNK_pyreq2323 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, threat intel. Also known as UNK_OutFlareAZ. ATT&CK coverage spans 29 techniques across 10 tactics in 2 of 2 tracked threats. Most-observed techniques: T1036 (Masquerading), T1110 (Brute Force), T1201 (Password Policy Discovery).

Tracked threats
22 high
First seen
2026-07-14
Last seen
2026-07-14
ATT&CK techniques
29across 2 of 2 threats
Related CVEs
0None referenced
2 tracked threat(s) · Categories: VULNERABILITY, THREAT_INTEL

Activity timeline

UNK_pyreq2323 appears in 2 tracked threats between and .

ATT&CK techniques observed

29 techniques observed across 2 of 2 tracked threats · Resource Development (6), Credential Access (4), Reconnaissance (4), Defense Impairment (3), Discovery (3), Initial Access (3)
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1110 Brute Force — Credential Accessobserved in 2 of 2 tracked threats
  • T1201 Password Policy Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1589 Gather Victim Identity Information — Reconnaissanceobserved in 2 of 2 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 1 of 2 tracked threats
  • T1078.004 Cloud Accounts — Initial Accessobserved in 1 of 2 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1087.004 Cloud Account — Discoveryobserved in 1 of 2 tracked threats
  • T1090 Proxy — Command and Controlobserved in 1 of 2 tracked threats
  • T1110.001 Password Guessing — Credential Accessobserved in 1 of 2 tracked threats
  • T1110.003 Password Spraying — Credential Accessobserved in 1 of 2 tracked threats
  • T1110.004 Credential Stuffing — Credential Accessobserved in 1 of 2 tracked threats
  • T1119 Automated Collection — Collectionobserved in 1 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 1 of 2 tracked threats

Tracked threats