OAuth Client ID Spoofing: A Stealthy Attack on Microsoft Entra Credentials (2026)

In today's digital landscape, where cloud security is paramount, a new threat has emerged that highlights the evolving nature of cyberattacks. This article delves into the world of OAuth client ID spoofing, a technique employed by malicious actors to exploit vulnerabilities in Microsoft Entra credentials.

The Rise of OAuth Client ID Spoofing

OAuth client ID spoofing is a sophisticated evasion tactic that allows attackers to validate stolen credentials without triggering any successful sign-in events. This stealthy approach has been observed in the wild, with at least two distinct threat actors utilizing it to gain unauthorized access to cloud services.

What makes this particularly fascinating is the way these attackers exploit a blind spot in cloud sign-in telemetry. By manipulating the OAuth client ID, a unique identifier assigned to applications, they can infer valid usernames and passwords at scale. This technique effectively checks stolen credential lists without leaving any obvious traces, making it challenging for defenders to detect and mitigate such attacks.

Unraveling the Technique

The attacks leverage the OAuth client ID, which is passed as "client_id" in authentication requests. By providing spoofed client IDs, attackers can perform account enumeration without the need for a registered OAuth application. This allows them to infer both password and account validity, all while avoiding the generation of a successful sign-in event.

One threat cluster, UNK_CustomCloak, has been observed employing this technique in brute-force campaigns targeting Microsoft Entra ID environments. They exploit a legacy application called Windows Live Custom Domains to bypass standard sign-in restrictions and probe user passwords across thousands of tenants.

The latest evolution of this tradecraft involves spoofing OAuth client IDs via HTTP POST requests to Microsoft's OAuth 2.0 token endpoint. By using the Resource Owner Password Credentials (ROPC) flow, attackers supply syntactically valid but non-existent client IDs. This enables them to analyze the error responses and identify valid accounts and passwords without a registered application.

Impact and Implications

The implications of OAuth client ID spoofing are significant. Armed with the ability to validate stolen credentials stealthily, attackers can identify accounts that provide them with unauthorized access. This not only compromises the security of organizations but also makes it difficult for defenders to detect and respond to such attacks.

Proofpoint, a cybersecurity firm, has identified two large campaigns that independently adopted this technique towards the end of 2025. These campaigns, UNKpyreq2323 and UNKOutFlareAZ, targeted millions of users and caused lockouts for a substantial number of targeted accounts. The use of valid UUIDs and precompiled username wordlists further demonstrates the sophistication and effectiveness of this attack vector.

A Step Towards Stealthy Access

The information gathered through OAuth client ID spoofing empowers attackers to identify accounts that can be exploited for stealthy access. By fragmenting authentication attempts across many fictional applications, the activity becomes harder to correlate, potentially evading per-application detections and rate limiting.

This raises a deeper question: How can organizations mitigate the risks associated with OAuth client ID spoofing? The answer lies in implementing robust security measures and staying vigilant. Applying Conditional Access policies scoped to commonly targeted applications can help mitigate traditional enumeration attacks. Additionally, continuous monitoring and analysis of sign-in logs are crucial to identifying suspicious activity and responding promptly.

Conclusion

In a rapidly evolving threat landscape, staying ahead of cybercriminals is a constant challenge. The emergence of OAuth client ID spoofing underscores the need for organizations to adapt and enhance their security strategies. By understanding the techniques employed by attackers and implementing proactive measures, we can better protect our digital assets and maintain a secure cloud environment.

OAuth Client ID Spoofing: A Stealthy Attack on Microsoft Entra Credentials (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Mr. See Jast

Last Updated:

Views: 5706

Rating: 4.4 / 5 (55 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.