# UNK_pyreq2323

> As of 2026-07-14, UNK_pyreq2323 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, threat intel. Also known as UNK_OutFlareAZ. ATT&CK coverage spans 29 techniques across 10 tactics in 2 of 2 tracked threats. Most-observed techniques: T1036 (Masquerading), T1110 (Brute Force), T1201 (Password Policy Discovery).

- **Tracked threats:** 2
- **Categories:** VULNERABILITY, THREAT_INTEL
- **Also known as:** UNK_OutFlareAZ
- **As of:** 2026-07-14

## ATT&CK techniques observed

29 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (6), Credential Access (4), Reconnaissance (4), Defense Impairment (3), Discovery (3), Initial Access (3).

- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 2 of 2 tracked threats
- [T1201](https://attack.mitre.org/techniques/T1201/) Password Policy Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 2 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 1 of 2 tracked threats
- [T1078.004](https://intel.threadlinqs.com/technique/T1078.004) Cloud Accounts — Initial Access — observed in 1 of 2 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1087.004](https://intel.threadlinqs.com/technique/T1087.004) Cloud Account — Discovery — observed in 1 of 2 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 1 of 2 tracked threats
- [T1110.001](https://intel.threadlinqs.com/technique/T1110.001) Password Guessing — Credential Access — observed in 1 of 2 tracked threats
- [T1110.003](https://intel.threadlinqs.com/technique/T1110.003) Password Spraying — Credential Access — observed in 1 of 2 tracked threats
- [T1110.004](https://intel.threadlinqs.com/technique/T1110.004) Credential Stuffing — Credential Access — observed in 1 of 2 tracked threats
- [T1119](https://intel.threadlinqs.com/technique/T1119) Automated Collection — Collection — observed in 1 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 1 of 2 tracked threats

## Tracked threats

- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 & UNK_OutFlareAZ](https://intel.threadlinqs.com/threat/TL-2026-1342) — HIGH
- [OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)](https://intel.threadlinqs.com/threat/TL-2026-1321) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNK_pyreq2323
