Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
Attackers are using spoofed OAuth client IDs to identify valid Microsoft Entra ID accounts and test credentials while avoiding many application-based signals commonly used to detect malicious authentication activity.
New research from Proofpoint documents multiple campaigns using the technique against millions of accounts in thousands of Microsoft Entra tenants. The campaigns used different infrastructure, tools and request patterns, indicating that multiple threat actors have independently adopted OAuth client ID spoofing.
Unlike an OAuth application compromise, the activity does not require attackers to register an application or exploit a vulnerability. Attackers only need to submit authentication requests with spoofed client IDs and examine the error responses returned by Microsoft Entra ID.
Those responses can reveal whether a username exists, whether a password is incorrect and, in some cases, whether a valid username and password combination has been supplied. Attackers can obtain this information without completing a successful sign-in.
Proofpoint’s report...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE