UNK_pyreq2323 is an unattributed threat activity cluster associated with large-scale account and credential enumeration against Microsoft Entra ID. The campaign abused OAuth client ID spoofing in the OAuth 2.0 Resource Owner Password Credentials (ROPC) flow, submitting usernames, passwords, and fabricated application identifiers to elicit distinct Entra ID error responses that reveal whether accounts exist and whether supplied credentials are valid. This tradecraft enables credential validation without producing a successful sign-in event and fragments malicious activity across hundreds of thousands of disposable application identifiers, reducing the effectiveness of detections keyed to known application names or single client IDs. The cluster was observed beginning in January 2026 and operated from Amazon Web Services infrastructure using the python-requests/2.32.3 user agent. It generated more than 700,000 spoofed client IDs by mutating the trailing digits of a legitimate Exchange Online application identifier and reused each spoofed identifier against only a small number of accounts before discarding it. Reported activity targeted more than one million user accounts across nearly 4,000 Entra ID tenants and caused account lockouts for roughly 28 percent of affected users due to repeated failed authentication attempts. Observed behavior supports assessment of systematic cloud account reconnaissance and credential-theft-oriented validation activity rather than ransomware or disruptive operations. The actor’s capabilities include large-scale password spraying or brute-force-style credential testing, use of spoofed OAuth application identifiers for defense evasion, and cloud-focused reconnaissance against identity infrastructure. Attribution remains low confidence, and available reporting indicates this cluster appears operationally distinct from the separately tracked UNK_OutFlareAZ campaign, which adopted similar OAuth client ID spoofing tradecraft with different infrastructure and identifier-generation methods.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enumeration campaign abusing OAuth 2.0 ROPC and spoofed OAuth client IDs to enumerate Microsoft Entra ID accounts and validate credentials while evading per-application detection thresholds.
Credential enumeration campaign abusing OAuth 2.0 ROPC and fabricated OAuth client IDs against Microsoft Entra ID to validate usernames and passwords while fragmenting activity across spoofed application identifiers.
Conducting account enumeration and credential validation against Microsoft Entra ID tenants via OAuth client ID spoofing using the ROPC flow.
Large-scale account enumeration and credential validation campaign abusing spoofed OAuth client IDs against Microsoft Entra ID tenants.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.