OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)

OAuth Client ID Spoofing Enables Stealthy Enumeration and (TL-2026-1321), also tracked as OAuth Client ID Spoofing, is a high-severity tracked intrusion set, first published 2026-07-14. It is attributed to UNK_pyreq2323 with medium confidence, affects Microsoft Entra ID (Azure AD) - Resource Owner Password Credentials, maps to 13 MITRE ATT&CK techniques (T1036, T1078, T1087), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1321

Threat ID
TL-2026-1321
Also known as
OAuth Client ID Spoofing, Entra ID ROPC Enumeration Abuse
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-14
Last reviewed
2026-07-14
Attribution
UNK_pyreq2323
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
technology, finance, government administration, health, education, professional-services, retail
Target regions
Global, North America
Detection rules
9
Indicators of compromise
20

Malware and tooling in OAuth Client ID Spoofing Enables Stealthy Enumeration and

Malware and tooling: TeamFiltration

Two distinct threat clusters — UNK_pyreq2323 and UNK_OutFlareAZ — are abusing the Resource Owner Password Credentials (ROPC) OAuth 2.0 flow against Microsoft Entra ID by submitting spoofed/fabricated client IDs alongside candidate credentials. Because Entra ID returns distinct AADSTS error codes for invalid app IDs, invalid usernames, and invalid passwords, attackers can enumerate valid accounts and validate stolen credentials at scale while sign-in logs record only failed attempts with a blank application name field, blinding per-application detections.

How OAuth Client ID Spoofing Enables Stealthy Enumeration and works

Proofpoint threat research disclosed a stealthy account-enumeration and credential-validation technique that abuses Microsoft Entra ID's Resource Owner Password Credentials (ROPC) OAuth 2.0 grant. Entra ID's token endpoint (login.microsoftonline.com) accepts a client_id parameter identifying the calling application. When an attacker submits an arbitrary or non-existent client_id together with a username/password pair, Entra ID does not reject the request outright even when the client_id is not a well-formed UUIDv4. Instead, it evaluates the credentials first and only then flags the unrecognized application, returning AADSTS700016 (application identifier not recognized) when the username and password are BOTH valid. Combined with AADSTS50034 (username does not exist, not written to the sign-in log) and AADSTS50126 (valid username, invalid password), the three distinct error codes give an attacker an oracle: they can enumerate which usernames exist in a tenant and separately confirm whether stolen/guessed passwords are correct, all without ever completing a successful sign-in event and without MFA ever being invoked (ROPC is a legacy non-interactive flow that predates modern MFA challenge support). Crucially, when the client_id is spoofed/unregistered, Entra ID's sign-in log entry is written with a BLANK application name field, so defenses and hunts that pivot on 'which app is failing logins' or scope Conditional Access policies to specific first-party application IDs never fire.

Two independent threat clusters were observed operationalizing this technique at internet scale. UNK_pyreq2323 (first observed 2026-01-14, active through early March 2026) operated from AWS-hosted infrastructure using the default python-requests/2.32.3 HTTP client user agent, generating spoofed client IDs by taking the legitimate Microsoft Exchange Online first-party application ID prefix (00000002-0000-0ff1-ce00-) and randomizing the trailing six hex digits to a non-zero value, reusing each fabricated ID against as many as 12 different target usernames before rotating. The campaign targeted over 1 million unique user accounts across roughly 4,000 Entra ID tenants using 700,000+ distinct spoofed client IDs, and caused account lockouts (via Entra ID smart lockout / conditional access thresholds) for approximately 28% of targeted users — collateral damage consistent with brute-force/password-spray velocity rather than careful low-and-slow enumeration.

UNK_OutFlareAZ (first observed December 2025, continuing through at least March 2026 in two distinct waves — a December 2025 wave peaking near 242,000 targeted users and a second wave peaking around 2026-03-15 at roughly 720,000 targeted users) originated primarily from Cloudflare-fronted infrastructure and forged a Microsoft Outlook desktop client user agent string (Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.12026; Pro...)) to blend into legitimate Outlook ROPC traffic patterns still seen from older desktop mail clients. Rather than reusing a recognizable Microsoft application ID prefix, UNK_OutFlareAZ generated a fully random UUIDv4 client_id for every single authentication attempt (3.7 million distinct spoofed client IDs against 2 million+ targeted users), and enumerated common/generic username patterns (e.g., dsmith, msmith, jbrown-style first-initial-lastname handles) alphabetically across many tenants simultaneously — a pattern consistent with automated dictionary-driven enumeration rather than a targeted list.

Proofpoint assesses the two clusters as independently operated (distinct infrastructure, user-agent, client-ID-generation strategy, and targeting cadence) rather than a single actor, indicating that OAuth client ID spoofing against ROPC is becoming broadly adopted tradecraft rather than a single group's bespoke tooling. The technique is closely related to, and likely compounds, the ongoing large-scale ROPC password-spray activity against Microsoft 365/Entra ID and Azure CLI's well-known first-party client ID (04b07795-8ddb-461a-bbee-02f9e1bf7b46) reported separately by Huntress (81M+ login attempts, June 2026), underscoring that ROPC itself — a legacy, non-interactive, MFA-incompatible OAuth grant — remains a persistently attractive target surface across the identity threat landscape. No CVE applies: this is abuse of legitimate, documented OAuth 2.0 / Entra ID mechanics (RFC 6749 ROPC grant plus Entra ID's error-response behavior), not a software vulnerability, but it qualifies as an actively exploited technique at massive scale against widely used cloud identity infrastructure.

MITRE ATT&CK techniques used in TL-2026-1321

Defense Evasion

T1036 Masquerading

Initial Access

T1078 Valid Accounts

Discovery

T1087 Account Discovery; T1201 Password Policy Discovery

command-and-control

T1090 Proxy

Credential Access

T1110 Brute Force

Collection

T1119 Automated Collection

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in OAuth Client ID Spoofing Enables Stealthy Enumeration and

  • Microsoft — Entra ID (Azure AD) - Resource Owner Password Credentials (ROPC) OAuth 2.0 grant
    Vulnerable versions: all tenants with ROPC / legacy authentication enabled
    Fixed in: N/A - mitigated via Conditional Access blocking legacy authentication / disabling ROPC
  • Microsoft — Exchange Online first-party application (client ID prefix 00000002-0000-0ff1-ce00-)
    Vulnerable versions: client ID namespace impersonated by UNK_pyreq2323
  • Microsoft — Azure CLI first-party application (client ID 04b07795-8ddb-461a-bbee-02f9e1bf7b46)
    Vulnerable versions: commonly abused for related ROPC password-spray activity (Huntress-reported campaign)

Remediation for OAuth Client ID Spoofing Enables Stealthy Enumeration and

Immediate actions

  • Hunt Entra ID sign-in logs for entries with a blank/missing application name field combined with AADSTS700016, treating these as potential valid-credential hits rather than benign failed logins
  • Alert on AADSTS700016 occurring alongside a non-standard or non-UUIDv4 client_id value in the sign-in log
  • Block or throttle authentication attempts using the ROPC (Resource Owner Password Credentials) grant type for user accounts/applications that do not have a documented business need for it
  • Review and rotate credentials for any accounts observed receiving AADSTS700016 responses, since this error can mask a valid username/password pair
  • Correlate ROPC sign-in attempts against source ASN/IP reputation — AWS and Cloudflare-fronted client traffic making high-volume ROPC requests is anomalous for most tenants

Workarounds

  • Where ROPC cannot be immediately disabled, enforce per-application Conditional Access location/IP allow-listing and require registered (non-spoofable) client IDs for any first-party app relied upon for automation

Longer-term hardening

  • Disable the ROPC grant type tenant-wide via Conditional Access 'block legacy authentication' policies unless a specific, documented, monitored exception exists
  • Move any legitimate ROPC-dependent legacy applications to modern auth (Authorization Code + PKCE) flows that support Conditional Access and MFA
  • Deploy Conditional Access policies that key on authentication_protocol=ROPC combined with anomalous client IP/ASN/velocity rather than solely on application ID, since spoofed client IDs bypass per-application scoping
  • Enable and monitor Entra ID smart lockout and sign-in risk policies tuned to the higher-volume, distributed pattern these campaigns exhibit
  • Deploy detection content (Sentinel/Elastic/Splunk) that treats missing application-name sign-in log entries as a first-class detection signal, not noise to be filtered

Weaknesses (CWE) in OAuth Client ID Spoofing Enables Stealthy Enumeration and

CWE-287, CWE-307, CWE-778

Timeline of OAuth Client ID Spoofing Enables Stealthy Enumeration and

  • UNK_OutFlareAZ begins Wave 1 of its OAuth client ID spoofing enumeration campaign against Microsoft Entra ID, originating primarily from Cloudflare-fronted infrastructure.
  • UNK_OutFlareAZ Wave 1 activity peaks at approximately 242,000 targeted user accounts.
  • UNK_pyreq2323 begins operating from AWS-hosted infrastructure, spoofing client IDs by randomizing the trailing digits of the legitimate Exchange Online application ID prefix (00000002-0000-0ff1-ce00-).
  • UNK_pyreq2323 activity reaches peak volume (late January through early February window), eventually spoofing 700,000+ client IDs against 1 million+ accounts across ~4,000 Entra ID tenants.
  • Account lockouts attributable to UNK_pyreq2323's high-velocity enumeration are observed affecting roughly 28% of targeted users.
  • UNK_OutFlareAZ begins a second, larger wave of enumeration activity following the December 2025 wave.
  • UNK_pyreq2323 activity begins tapering off after roughly seven weeks of sustained enumeration.
  • UNK_OutFlareAZ Wave 2 activity peaks at approximately 720,000 targeted users, using a fully randomized UUIDv4 client ID per authentication attempt and a forged Microsoft Outlook desktop user agent.
  • Huntress begins observing a related, separately tracked mass ROPC password-spray campaign against Microsoft 365/Entra ID via the Azure CLI first-party application ID, eventually logging 81 million+ login attempts by 2026-06-26.
  • Proofpoint publishes threat research publicly disclosing the OAuth client ID spoofing technique, detailing both the UNK_pyreq2323 and UNK_OutFlareAZ clusters and the underlying AADSTS error-code enumeration oracle.
  • Broad security media coverage (The Hacker News, Help Net Security, Infosecurity Magazine, SC World, Cyberpress, Hackread) amplifies the Proofpoint findings, driving defender awareness and hunt activity.

Sources cited for OAuth Client ID Spoofing Enables Stealthy Enumeration and

Threats related to OAuth Client ID Spoofing Enables Stealthy Enumeration and

Detection coverage for TL-2026-1321

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1321 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats