# Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flow

> Huntress observed a 155-fold increase in credential spraying attacks during H1 2026, with over 81 million login attempts recorded in a single two-week window targeting Microsoft Azure CLI via the deprecated ROPC OAuth 2.0 grant. The ROPC flow bypasses MFA and Conditional Access Policies by sending credentials directly to the /token endpoint, minting user-delegated tokens without any interactive challenge. 78 accounts were compromised across 64 organizations; attackers leveraged BYOIP infrastructure from LSHIY LLC, FranTech, and 3xK Tech hosting providers with sustained volumes of ~1.5 million attempts per day.

- **Published:** 2026-08-19T00:00:00Z
- **Last reviewed:** 2026-08-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2071
- **ID:** TL-2026-2071
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Huntress documented a massive, ongoing automated password spray campaign targeting Microsoft 365 environments via Azure CLI, originating from a network of hosting providers offering minimal oversight. The campaign represents a 155-fold increase in credential spraying attacks across the Huntress customer base in H1 2026, with mean failed attacks of ~1,964 per month per tenant (median 804), indicating heavy skew toward the most targeted organizations.

At the core of the attack is the Resource Owner Password Credentials (ROPC) OAuth 2.0 grant, a legacy authentication flow deprecated in OAuth 2.1. Originally designed to help migrate legacy auth to OAuth, ROPC allows an application to trade a username and password directly at the /token endpoint for a user-delegated access token. Unlike interactive OAuth flows, ROPC never passes through the authorization endpoint where Conditional Access Policies (CAPs) are evaluated, meaning MFA challenges are never triggered. The attack specifically targeted Microsoft's Azure CLI application, using the ROPC flow to authenticate against tenant /token endpoints.

Of 78 compromised accounts analyzed across 23 businesses, only 8 had no MFA at all. The remaining 15 had MFA implemented but misconfigured: MFA was scoped to specific apps (e.g., Admin Portals) rather than covering all cloud apps; scoped to specific user groups (e.g., Admins Only) that excluded compromised accounts; conditioned on trusted locations that attacker IPs evaded due to inconsistent IPv6 geolocation; left in report-only mode (configured but never enforced); or in one case, a policy explicitly named "Block Azure CLI" that did not actually block Azure CLI. The ROPC flow was simply not covered by the existing CAP configurations.

The adversary infrastructure evolved through three distinct hosting providers. The initial wave (June 2026) originated from LSHIY LLC (AS32167, AS955), using the IPv6 range 2a0a:d683::/32. LSHIY's Bring Your Own IP (BYOIP) offering allowed the attacker to peer their own IP address ranges through LSHIY's network, evading Microsoft's Smart Lockout and other reputation-based detection. After Huntress reported the abuse, LSHIY suspended the user's service in early July. The attacker immediately migrated to FranTech (AS53667) using IPv6 ranges 2605:6400::/32 and 2605:6404::/32, with 87% of targeted accounts overlapping with the LSHIY wave. A third wave then moved to 3xK Tech GmbH (AS200373), a German ISP previously identified as the largest source of ASN DDoS attacks by Cloudflare. On 3xK Tech, the attacker shifted from IPv6 to IPv4, rotating through approximately 12,800 IPs with each limited to ~900 attempts, restoring volume to ~1.5 million login attempts per day.

The attack methodology followed a multi-stage pattern: reconnaissance via LinkedIn, company websites, and prior breach dumps to collect valid usernames; assembly of password lists from breached credential combo lists, common passwords, company name variants, and seasonal terms; low-and-slow spraying with one password per account and delays between attempts to avoid lockout thresholds; and credential reuse from previously breached username/password pairs that were never rotated. Huntress observed no post-compromise activity, leading researchers to assess that the attacker was validating credentials for sale on the dark web.

Detection signals include anomalous IP geolocation (logins from China for US-based organizations), failed login volume analysis, ASN-based tracking of the three hosting providers, and ROPC-specific authentication protocol detection in Entra ID sign-in logs. The AuthenticationProtocol field in SigninLogs contains the value 'ropc' for these flows, and Azure CLI logins use the UserAgent 'node-fetch' when automated. The Azure CLI app ID is 04b07795-8ddb-461a-bbee-02f9e1bf7b46. Elastic has published a prebuilt detection rule for Entra ID OAuth ROPC Grant logins.

Microsoft's recommended mitigation is the userStrongAuthClientAuthNRequired setting, which enforces strong authentication at the client level and blocks ROPC flows outright. Additional mitigations include requiring MFA for all users, all cloud apps, and all client app types unconditionally; restricting Azure CLI application access for non-admin users; and disabling the ROPC grant type where possible. The campaign is not targeting any specific industry but rather opportunistically targeting organizations with poor password hygiene or improperly configured Conditional Access Policies.

## MITRE ATT&CK

- T1589.003 Gather Victim Identity Information: Employee Names
- T1589.001 Gather Victim Identity Information: Credentials
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1584.004 Compromise Infrastructure: Server
- T1078 Valid Accounts
- T1078.004 Valid Accounts: Cloud Accounts
- T1133 External Remote Services
- T1110.001 Brute Force: Password Guessing
- T1110.003 Brute Force: Password Spraying
- T1528 Steal Application Access Token

## Sources

- [BleepingComputer — Password spraying attacks surge 155x as hackers exploit MFA gaps](https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/)
- [Huntress — No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack](https://www.huntress.com/blog/lshiy-password-spray-attack)
- [Huntress — Twist the Nozzle on Password Spraying: A Tradecraft Tuesday Recap](https://www.huntress.com/blog/twist-the-nozzle-on-password-spraying-a-tradecraft-tuesday-recap)
- [Huntress — Railway. LSHIY. Different Auth Flows, but the Same Lesson We Keep Skipping](https://www.huntress.com/blog/conditional-access-misconfigurations)
- [Huntress — Password Spraying Attacks in Microsoft 365: Detection, Tools & Defense](https://www.huntress.com/blog/password-spraying-attacks-microsoft-365-defense)
- [Elastic — Prebuilt Detection Rule: Entra ID OAuth ROPC Grant Login Detected](https://www.elastic.co/security/rules/entra-id-oauth-ropc-grant)
- [FNDSEC — Evading EntraID Conditional Access Policies via Cross-Tenant ROPC](https://blog.fndsec.net/2026/01/13/evading-entraid-conditional-access-policies-via-cross-tenant-ropc/)
- [Hive Security — LSHIY Password Spray: ROPC and MFA Gaps](https://hivesecurity.gitlab.io/blog/lshiy-password-spray-ropc-mfa-bypass-2026/)
- [KQL Search — Azure CLI Spray Detection Query (ASN 53667)](https://www.kqlsearch.com/query/Azure%20CLI%20Spray%20-%20ASN%2053667)
- [Modern42 — Conditional Access Resource Exclusions + SIEM Detection](https://www.modern42.com/blog/microsoft-entra-id-conditional-access-resource-exclusions)
- [IntrusionLabs — FranTech AS53667 SSH Brute-Force Campaign](https://intrusionlabs.io/reports/2026/franTech-as53667)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2071
