UNK_OutFlareAZ is an unattributed threat activity cluster associated with large-scale account and credential enumeration against Microsoft Entra ID. Active from December 2025 and observed again in February and March 2026, the campaign abused the OAuth 2.0 Resource Owner Password Credentials (ROPC) flow and spoofed OAuth client identifiers to validate usernames and passwords without using a legitimate registered application. Its tradecraft relied on submitting fabricated but syntactically valid client IDs so that Entra ID returned distinct authentication error codes that exposed whether usernames existed and whether supplied passwords were correct, while avoiding successful sign-in events and degrading detections based on known application names or application-scoped thresholds. The campaign operated primarily through Cloudflare infrastructure and used a more mature identifier-generation approach than related activity, creating a fresh random UUIDv4 client ID for every request to limit correlation. Observed behavior included systematic, wordlist-driven username enumeration with alphabetic progression across generic usernames, indicating broad credential-validation activity across many organizations. By the time it was documented, the cluster had used approximately 3.7 million spoofed application IDs against more than two million accounts. Attribution remains unconfirmed, but the activity is consistent with a credential-focused cloud identity attack cluster conducting stealthy password validation and account enumeration at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enumeration campaign abusing OAuth 2.0 ROPC and spoofed OAuth client IDs to enumerate Microsoft Entra ID accounts and validate credentials while evading per-application detection thresholds.
Large-scale credential enumeration campaign abusing OAuth 2.0 ROPC and spoofed OAuth client IDs against Microsoft Entra ID, using a fresh random UUID per request to evade application-centric detections.
Conducting large-scale account enumeration and credential validation against Microsoft Entra ID tenants via OAuth client ID spoofing with randomized client IDs.
Massive Entra ID account enumeration and credential-checking campaign using spoofed OAuth client IDs, random UUIDv4 client IDs, and a forged Microsoft Outlook user agent.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.