OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)
OAuth Client ID Spoofing Enables Stealthy Enumeration and (TL-2026-1321), also tracked as OAuth Client ID Spoofing, is a high-severity tracked intrusion set, first published 2026-07-14. It is attributed to UNK_pyreq2323 with medium confidence, affects Microsoft Entra ID (Azure AD) - Resource Owner Password Credentials, maps to 13 MITRE ATT&CK techniques (T1036, T1078, T1087), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1321
- Threat ID
- TL-2026-1321
- Also known as
- OAuth Client ID Spoofing, Entra ID ROPC Enumeration Abuse
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- UNK_pyreq2323
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, government administration, health, education, professional-services, retail
- Target regions
- Global, North America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in OAuth Client ID Spoofing Enables Stealthy Enumeration and
Malware and tooling: TeamFiltration
Two distinct threat clusters — UNK_pyreq2323 and UNK_OutFlareAZ — are abusing the Resource Owner Password Credentials (ROPC) OAuth 2.0 flow against Microsoft Entra ID by submitting spoofed/fabricated client IDs alongside candidate credentials. Because Entra ID returns distinct AADSTS error codes for invalid app IDs, invalid usernames, and invalid passwords, attackers can enumerate valid accounts and validate stolen credentials at scale while sign-in logs record only failed attempts with a blank application name field, blinding per-application detections.
How OAuth Client ID Spoofing Enables Stealthy Enumeration and works
Proofpoint threat research disclosed a stealthy account-enumeration and credential-validation technique that abuses Microsoft Entra ID's Resource Owner Password Credentials (ROPC) OAuth 2.0 grant. Entra ID's token endpoint (login.microsoftonline.com) accepts a client_id parameter identifying the calling application. When an attacker submits an arbitrary or non-existent client_id together with a username/password pair, Entra ID does not reject the request outright even when the client_id is not a well-formed UUIDv4. Instead, it evaluates the credentials first and only then flags the unrecognized application, returning AADSTS700016 (application identifier not recognized) when the username and password are BOTH valid. Combined with AADSTS50034 (username does not exist, not written to the sign-in log) and AADSTS50126 (valid username, invalid password), the three distinct error codes give an attacker an oracle: they can enumerate which usernames exist in a tenant and separately confirm whether stolen/guessed passwords are correct, all without ever completing a successful sign-in event and without MFA ever being invoked (ROPC is a legacy non-interactive flow that predates modern MFA challenge support). Crucially, when the client_id is spoofed/unregistered, Entra ID's sign-in log entry is written with a BLANK application name field, so defenses and hunts that pivot on 'which app is failing logins' or scope Conditional Access policies to specific first-party application IDs never fire.
Two independent threat clusters were observed operationalizing this technique at internet scale. UNK_pyreq2323 (first observed 2026-01-14, active through early March 2026) operated from AWS-hosted infrastructure using the default python-requests/2.32.3 HTTP client user agent, generating spoofed client IDs by taking the legitimate Microsoft Exchange Online first-party application ID prefix (00000002-0000-0ff1-ce00-) and randomizing the trailing six hex digits to a non-zero value, reusing each fabricated ID against as many as 12 different target usernames before rotating. The campaign targeted over 1 million unique user accounts across roughly 4,000 Entra ID tenants using 700,000+ distinct spoofed client IDs, and caused account lockouts (via Entra ID smart lockout / conditional access thresholds) for approximately 28% of targeted users — collateral damage consistent with brute-force/password-spray velocity rather than careful low-and-slow enumeration.
UNK_OutFlareAZ (first observed December 2025, continuing through at least March 2026 in two distinct waves — a December 2025 wave peaking near 242,000 targeted users and a second wave peaking around 2026-03-15 at roughly 720,000 targeted users) originated primarily from Cloudflare-fronted infrastructure and forged a Microsoft Outlook desktop client user agent string (Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.12026; Pro...)) to blend into legitimate Outlook ROPC traffic patterns still seen from older desktop mail clients. Rather than reusing a recognizable Microsoft application ID prefix, UNK_OutFlareAZ generated a fully random UUIDv4 client_id for every single authentication attempt (3.7 million distinct spoofed client IDs against 2 million+ targeted users), and enumerated common/generic username patterns (e.g., dsmith, msmith, jbrown-style first-initial-lastname handles) alphabetically across many tenants simultaneously — a pattern consistent with automated dictionary-driven enumeration rather than a targeted list.
Proofpoint assesses the two clusters as independently operated (distinct infrastructure, user-agent, client-ID-generation strategy, and targeting cadence) rather than a single actor, indicating that OAuth client ID spoofing against ROPC is becoming broadly adopted tradecraft rather than a single group's bespoke tooling. The technique is closely related to, and likely compounds, the ongoing large-scale ROPC password-spray activity against Microsoft 365/Entra ID and Azure CLI's well-known first-party client ID (04b07795-8ddb-461a-bbee-02f9e1bf7b46) reported separately by Huntress (81M+ login attempts, June 2026), underscoring that ROPC itself — a legacy, non-interactive, MFA-incompatible OAuth grant — remains a persistently attractive target surface across the identity threat landscape. No CVE applies: this is abuse of legitimate, documented OAuth 2.0 / Entra ID mechanics (RFC 6749 ROPC grant plus Entra ID's error-response behavior), not a software vulnerability, but it qualifies as an actively exploited technique at massive scale against widely used cloud identity infrastructure.
MITRE ATT&CK techniques used in TL-2026-1321
Defense Evasion
Initial Access
Discovery
T1087 Account Discovery; T1201 Password Policy Discovery
command-and-control
Credential Access
Collection
defense-impairment
T1556 Modify Authentication Process; T1685 Disable or Modify Tools
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in OAuth Client ID Spoofing Enables Stealthy Enumeration and
- Microsoft — Entra ID (Azure AD) - Resource Owner Password Credentials (ROPC) OAuth 2.0 grant
Vulnerable versions: all tenants with ROPC / legacy authentication enabled
Fixed in: N/A - mitigated via Conditional Access blocking legacy authentication / disabling ROPC - Microsoft — Exchange Online first-party application (client ID prefix 00000002-0000-0ff1-ce00-)
Vulnerable versions: client ID namespace impersonated by UNK_pyreq2323 - Microsoft — Azure CLI first-party application (client ID 04b07795-8ddb-461a-bbee-02f9e1bf7b46)
Vulnerable versions: commonly abused for related ROPC password-spray activity (Huntress-reported campaign)
Remediation for OAuth Client ID Spoofing Enables Stealthy Enumeration and
Immediate actions
- Hunt Entra ID sign-in logs for entries with a blank/missing application name field combined with AADSTS700016, treating these as potential valid-credential hits rather than benign failed logins
- Alert on AADSTS700016 occurring alongside a non-standard or non-UUIDv4 client_id value in the sign-in log
- Block or throttle authentication attempts using the ROPC (Resource Owner Password Credentials) grant type for user accounts/applications that do not have a documented business need for it
- Review and rotate credentials for any accounts observed receiving AADSTS700016 responses, since this error can mask a valid username/password pair
- Correlate ROPC sign-in attempts against source ASN/IP reputation — AWS and Cloudflare-fronted client traffic making high-volume ROPC requests is anomalous for most tenants
Workarounds
- Where ROPC cannot be immediately disabled, enforce per-application Conditional Access location/IP allow-listing and require registered (non-spoofable) client IDs for any first-party app relied upon for automation
Longer-term hardening
- Disable the ROPC grant type tenant-wide via Conditional Access 'block legacy authentication' policies unless a specific, documented, monitored exception exists
- Move any legitimate ROPC-dependent legacy applications to modern auth (Authorization Code + PKCE) flows that support Conditional Access and MFA
- Deploy Conditional Access policies that key on authentication_protocol=ROPC combined with anomalous client IP/ASN/velocity rather than solely on application ID, since spoofed client IDs bypass per-application scoping
- Enable and monitor Entra ID smart lockout and sign-in risk policies tuned to the higher-volume, distributed pattern these campaigns exhibit
- Deploy detection content (Sentinel/Elastic/Splunk) that treats missing application-name sign-in log entries as a first-class detection signal, not noise to be filtered
Weaknesses (CWE) in OAuth Client ID Spoofing Enables Stealthy Enumeration and
CWE-287, CWE-307, CWE-778
Timeline of OAuth Client ID Spoofing Enables Stealthy Enumeration and
- UNK_OutFlareAZ begins Wave 1 of its OAuth client ID spoofing enumeration campaign against Microsoft Entra ID, originating primarily from Cloudflare-fronted infrastructure.
- UNK_OutFlareAZ Wave 1 activity peaks at approximately 242,000 targeted user accounts.
- UNK_pyreq2323 begins operating from AWS-hosted infrastructure, spoofing client IDs by randomizing the trailing digits of the legitimate Exchange Online application ID prefix (00000002-0000-0ff1-ce00-).
- UNK_pyreq2323 activity reaches peak volume (late January through early February window), eventually spoofing 700,000+ client IDs against 1 million+ accounts across ~4,000 Entra ID tenants.
- Account lockouts attributable to UNK_pyreq2323's high-velocity enumeration are observed affecting roughly 28% of targeted users.
- UNK_OutFlareAZ begins a second, larger wave of enumeration activity following the December 2025 wave.
- UNK_pyreq2323 activity begins tapering off after roughly seven weeks of sustained enumeration.
- UNK_OutFlareAZ Wave 2 activity peaks at approximately 720,000 targeted users, using a fully randomized UUIDv4 client ID per authentication attempt and a forged Microsoft Outlook desktop user agent.
- Huntress begins observing a related, separately tracked mass ROPC password-spray campaign against Microsoft 365/Entra ID via the Azure CLI first-party application ID, eventually logging 81 million+ login attempts by 2026-06-26.
- Proofpoint publishes threat research publicly disclosing the OAuth client ID spoofing technique, detailing both the UNK_pyreq2323 and UNK_OutFlareAZ clusters and the underlying AADSTS error-code enumeration oracle.
- Broad security media coverage (The Hacker News, Help Net Security, Infosecurity Magazine, SC World, Cyberpress, Hackread) amplifies the Proofpoint findings, driving defender awareness and hunt activity.
Sources cited for OAuth Client ID Spoofing Enables Stealthy Enumeration and
- OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration
- Hackers Spoof OAuth Client IDs
- OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
- Fake Client IDs Are Gaining Traction for Stealthy Enumeration
- Fake OAuth client IDs are helping attackers slip past sign-in logs
- Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
- Hackers Abuse Fake OAuth Client IDs to Validate Microsoft Entra Accounts and Passwords
- Cybercriminals exploit OAuth client ID spoofing to bypass cloud security
- Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
- Entra ID OAuth ROPC Grant Login Detected
- Massive Password Spray Campaign Targeting Azure CLI
- Massive Password Stealing Attack Targeting Microsoft 365 Users With 81 Million Login Attempts
- Abusing ROPC to Bypass MFA — and How I Built a Detection for It in Microsoft Sentinel
Threats related to OAuth Client ID Spoofing Enables Stealthy Enumeration and
Detection coverage for TL-2026-1321
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1321 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.