Threat reportThreat IntelligenceTL-2026-2071
Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flow
Password spraying attacks surge 155x as hackers exploit MFA (TL-2026-2071), also tracked as LSHIY password spray campaign, is a high-severity tracked intrusion set, first published 2026-08-19. It has no confirmed attribution, affects Microsoft Azure CLI, maps to 10 MITRE ATT&CK techniques (T1078, T1078.004, T1110.001), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-2071
- Threat ID
- TL-2026-2071
- Also known as
- LSHIY password spray campaign, FranTech password spray wave, 3xK Tech password spray wave
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, education, finance, health, technology, manufacturing
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Password spraying attacks surge 155x as hackers exploit MFA
Malware and tooling: Microsoft Azure CLI
How Password spraying attacks surge 155x as hackers exploit MFA works
Huntress observed a 155-fold increase in credential spraying attacks during H1 2026, with over 81 million login attempts recorded in a single two-week window targeting Microsoft Azure CLI via the deprecated ROPC OAuth 2.0 grant. The ROPC flow bypasses MFA and Conditional Access Policies by sending credentials directly to the /token endpoint, minting user-delegated tokens without any interactive challenge. 78 accounts were compromised across 64 organizations; attackers leveraged BYOIP infrastructure from LSHIY LLC, FranTech, and 3xK Tech hosting providers with sustained volumes of ~1.5 million attempts per day.
Huntress documented a massive, ongoing automated password spray campaign targeting Microsoft 365 environments via Azure CLI, originating from a network of hosting providers offering minimal oversight. The campaign represents a 155-fold increase in credential spraying attacks across the Huntress customer base in H1 2026, with mean failed attacks of ~1,964 per month per tenant (median 804), indicating heavy skew toward the most targeted organizations.
At the core of the attack is the Resource Owner Password Credentials (ROPC) OAuth 2.0 grant, a legacy authentication flow deprecated in OAuth 2.1. Originally designed to help migrate legacy auth to OAuth, ROPC allows an application to trade a username and password directly at the /token endpoint for a user-delegated access token. Unlike interactive OAuth flows, ROPC never passes through the authorization endpoint where Conditional Access Policies (CAPs) are evaluated, meaning MFA challenges are never triggered. The attack specifically targeted Microsoft's Azure CLI application, using the ROPC flow to authenticate against tenant /token endpoints.
Of 78 compromised accounts analyzed across 23 businesses, only 8 had no MFA at all. The remaining 15 had MFA implemented but misconfigured: MFA was scoped to specific apps (e.g., Admin Portals) rather than covering all cloud apps; scoped to specific user groups (e.g., Admins Only) that excluded compromised accounts; conditioned on trusted locations that attacker IPs evaded due to inconsistent IPv6 geolocation; left in report-only mode (configured but never enforced); or in one case, a policy explicitly named "Block Azure CLI" that did not actually block Azure CLI. The ROPC flow was simply not covered by the existing CAP configurations.
The adversary infrastructure evolved through three distinct hosting providers. The initial wave (June 2026) originated from LSHIY LLC (AS32167, AS955), using the IPv6 range 2a0a:d683::/32. LSHIY's Bring Your Own IP (BYOIP) offering allowed the attacker to peer their own IP address ranges through LSHIY's network, evading Microsoft's Smart Lockout and other reputation-based detection. After Huntress reported the abuse, LSHIY suspended the user's service in early July. The attacker immediately migrated to FranTech (AS53667) using IPv6 ranges 2605:6400::/32 and 2605:6404::/32, with 87% of targeted accounts overlapping with the LSHIY wave. A third wave then moved to 3xK Tech GmbH (AS200373), a German ISP previously identified as the largest source of ASN DDoS attacks by Cloudflare. On 3xK Tech, the attacker shifted from IPv6 to IPv4, rotating through approximately 12,800 IPs with each limited to ~900 attempts, restoring volume to ~1.5 million login attempts per day.
The attack methodology followed a multi-stage pattern: reconnaissance via LinkedIn, company websites, and prior breach dumps to collect valid usernames; assembly of password lists from breached credential combo lists, common passwords, company name variants, and seasonal terms; low-and-slow spraying with one password per account and delays between attempts to avoid lockout thresholds; and credential reuse from previously breached username/password pairs that were never rotated. Huntress observed no post-compromise activity, leading researchers to assess that the attacker was validating credentials for sale on the dark web.
Detection signals include anomalous IP geolocation (logins from China for US-based organizations), failed login volume analysis, ASN-based tracking of the three hosting providers, and ROPC-specific authentication protocol detection in Entra ID sign-in logs. The AuthenticationProtocol field in SigninLogs contains the value 'ropc' for these flows, and Azure CLI logins use the UserAgent 'node-fetch' when automated. The Azure CLI app ID is 04b07795-8ddb-461a-bbee-02f9e1bf7b46. Elastic has published a prebuilt detection rule for Entra ID OAuth ROPC Grant logins.
Microsoft's recommended mitigation is the userStrongAuthClientAuthNRequired setting, which enforces strong authentication at the client level and blocks ROPC flows outright. Additional mitigations include requiring MFA for all users, all cloud apps, and all client app types unconditionally; restricting Azure CLI application access for non-admin users; and disabling the ROPC grant type where possible. The campaign is not targeting any specific industry but rather opportunistically targeting organizations with poor password hygiene or improperly configured Conditional Access Policies.
MITRE ATT&CK techniques used in TL-2026-2071
Initial Access
T1078 Valid Accounts; T1078.004 Valid Accounts: Cloud Accounts; T1133 External Remote Services
Credential Access
T1110.001 Brute Force: Password Guessing; T1110.003 Brute Force: Password Spraying; T1528 Steal Application Access Token
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1584.004 Compromise Infrastructure: Server
Reconnaissance
T1589.001 Gather Victim Identity Information: Credentials; T1589.003 Gather Victim Identity Information: Employee Names
Affected products and versions in Password spraying attacks surge 155x as hackers exploit MFA
Remediation for Password spraying attacks surge 155x as hackers exploit MFA
Immediate actions
- Enable userStrongAuthClientAuthNRequired in Entra ID to block ROPC flows outright
- Audit Conditional Access Policies to ensure MFA covers all cloud apps, all users, and all client app types
- Restrict Azure CLI application access for non-admin users
- Block legacy authentication flows including ROPC and device code flow
- Review sign-in logs for AuthenticationProtocol='ropc' combined with Azure CLI AppDisplayName
Workarounds
- Disable the ROPC grant type in tenant settings where legacy app compatibility is not required
- Block IPv6 ranges 2a0a:d683::/32, 2605:6400::/32, 2605:6404::/32 at perimeter
- Block ASNs AS32167, AS53667, AS200373 for authentication traffic
- Set Conditional Access policies to 'All Cloud Apps' and 'All Client App Types' including 'Other clients'
Longer-term hardening
- Transition to passwordless authentication methods (FIDO2, Windows Hello, Microsoft Authenticator)
- Replace user accounts in automation with managed identities or service principals
- Implement continuous access evaluation (CAE) for real-time policy enforcement
- Deploy SIEM rules for ROPC authentication monitoring across all tenants
- Establish baseline of normal ROPC usage per app/user over 14 days, then alert on deviations
Timeline of Password spraying attacks surge 155x as hackers exploit MFA
- IPv6 address maintainer in LSHIY LLC range (2a0a:d683::/32) created, marking the start of attack infrastructure preparation
- Steady trickle of account compromises begins at 2-4 accounts per day across Huntress-protected tenants
- 12 accounts compromised in a single day, the highest single-day count before the major spike
- Major spike: 30 accounts compromised across 23 businesses in a single day; Huntress analysis shows 15 of 23 had MFA but it was not configured to cover the ROPC flow
- End of two-week observation window: 78 accounts compromised across 64 organizations with 81 million+ login attempts recorded
- Huntress publishes initial blog post 'No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack' documenting the campaign
- LSHIY LLC suspends BYOIP user after Huntress abuse report; attacks from the 2a0a:d683::/32 range cease
- Activity shifts to 3xK Tech GmbH (AS200373) as a third hosting provider, using IPv4 with ~12,800 rotating IPs at ~900 attempts per IP
- Attackers migrate spray activity to FranTech (AS53667) using IPv6 ranges 2605:6400::/32 and 2605:6404::/32; 87% of targeted accounts overlap with the LSHIY wave
- Attackers restore spray volume to approximately 1.5 million login attempts per day from 3xK Tech, matching the LSHIY-era peak
- Huntress publishes update noting the 3xK Tech IPv4 low-and-slow approach, the shift from IPv6 to IPv4, and the per-IP volume limitation
- BleepingComputer publishes comprehensive summary of the campaign, noting the 155x increase in password spraying across H1 2026
Sources cited for Password spraying attacks surge 155x as hackers exploit MFA
- BleepingComputer — Password spraying attacks surge 155x as hackers exploit MFA gaps
- Huntress — No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
- Huntress — Twist the Nozzle on Password Spraying: A Tradecraft Tuesday Recap
- Huntress — Railway. LSHIY. Different Auth Flows, but the Same Lesson We Keep Skipping
- Huntress — Password Spraying Attacks in Microsoft 365: Detection, Tools & Defense
- Elastic — Prebuilt Detection Rule: Entra ID OAuth ROPC Grant Login Detected
- FNDSEC — Evading EntraID Conditional Access Policies via Cross-Tenant ROPC
- Hive Security — LSHIY Password Spray: ROPC and MFA Gaps
- KQL Search — Azure CLI Spray Detection Query (ASN 53667)
- Modern42 — Conditional Access Resource Exclusions + SIEM Detection
- IntrusionLabs — FranTech AS53667 SSH Brute-Force Campaign
Detection coverage for TL-2026-2071
As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2071 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.