Microsoft Entra OAuth Client ID spoofing campaign
Campaign
Summary
Hide ▲
Show ▼
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance that malicious logins go undetected. Proofpoint says it has tracked multiple large-scale campaigns affecting millions of user accounts across thousands of tenants. The activity relies on the ROPC flow and blank application fields to obscure authentication attempts.
Related Happenings
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware Activity
H score36
First: 30.06.2026 18:34
Last: 30.06.2026 18:34
Sources 1
About this happening:
The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware ActivityAbout this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Timeline
-
13.07.2026 16:00 3 articles · 13d ago
OAuth client ID spoofing evades Microsoft Entra ID sign-in logs
Initial DisclosureProofpoint describes attackers using OAuth client ID spoofing against Microsoft Entra ID to hide malicious authentication activity in Entra sign-in logs. The technique relies on POST requests to Microsoft's OAuth 2.0 token endpoint with the Resource Owner Password Credentials (ROPC) flow, spoofed IDs, and blank application fields, allowing operators to infer valid usernames and passwords, identify accounts that can be exploited, and potentially bypass detection while targeting cloud environments. Proofpoint also says it has tracked multiple large-scale campaigns affecting millions of user accounts across thousands of Microsoft Entra tenants, and advises defenders to treat blank application IDs, missing application names, and AADSTS700016 errors as possible indicators of client ID spoofing.
Show sources
- Novel OAuth Client ID Spoofing Technique Targets Cloud Environments — www.infosecurity-magazine.com — 13.07.2026 16:00
- Novel OAuth Client ID Spoofing Technique Targets Cloud Environments — www.infosecurity-magazine.com — 13.07.2026 16:00
- OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials — thehackernews.com — 14.07.2026 14:21