Proofpoint reported that attackers are increasingly abusing OAuth client ID spoofing against Microsoft Entra ID to enumerate accounts and validate credentials without registering a legitimate OAuth application. The activity relies on Resource Owner Password Credentials (ROPC) authentication requests that use spoofed or random client_id values, allowing attackers to distinguish invalid usernames, valid usernames with incorrect passwords, and in some cases valid username-password pairs based on Microsoft Entra AADSTS error responses.
Proofpoint said it observed at least two large-scale campaigns, UNK_pyreq2323 and UNK_OutFlareAZ, using different infrastructure, user agents, and client ID generation patterns, indicating the technique is being adopted by multiple threat actors. Microsoft’s published Entra error code behavior helps explain how responses such as AADSTS700016 can leak authentication state, and defenders were urged to review Entra sign-in logs for blank or missing application names or IDs and to treat some apparent failed logins as possible signs of successful credential validation by an attacker.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Proofpoint reported that attackers are increasingly abusing spoofed or random OAuth client_id values in ROPC authentication requests against Microsoft Entra ID to enumerate accounts and infer credential validity without registering an OAuth application. The company said it observed at least two large-scale campaigns, tracked as UNK_pyreq2323 and UNK_OutFlareAZ, indicating multiple threat actors have adopted the technique.
Microsoft published documentation for Microsoft Entra authentication and authorization error codes, including AADSTS responses that can reveal differences between invalid usernames, bad passwords, and other authentication states.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceproofpoint.com
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.