
Novel OAuth Client ID Spoofing Technique Exploited in Cloud Campaigns Targeting Microsoft Entra ID
CybersecurityCloudSecurityThreatIntelligenceHacking
At least two distinct threat actors are exploiting a novel evasion technique called OAuth client ID spoofing in cloud campaigns targeting Microsoft Entra ID environments. The method enables attackers to enumerate user accounts and validate stolen credentials without generating detectable sign-in events, evading standard security telemetry. No specific dates, CVE IDs, or technical implementation details were disclosed in the reported activity. The impact includes unauthorized credential validation and account reconnaissance while bypassing defensive alerts. The technique has been weaponized in active campaigns but no affected organizations or scale were specified.