Password Spraying Attacks Rise As Attackers Target Microsoft Azure MFA Gaps

Password Spraying Attacks Rise As Attackers Target Microsoft Azure MFA Gaps

Cybersecurity firm Huntress has reported a significant rise in password spraying attacks, observing a 155x increase during the first half of 2026 as attackers continue exploiting weaknesses in multi factor authentication protections. While brute force attacks remain a long standing cybersecurity threat, researchers said the latest activity shows attackers are using more targeted methods by combining large scale password spraying with previously exposed credentials and weaknesses in authentication processes. One of the major campaigns identified by Huntress targeted Microsoft Azure CLI, a command line tool used by administrators to manage Azure and Entra resources. The activity originated from an IPv6 range controlled by internet hosting provider LSHIY LLC. According to Huntress, the campaign began months earlier, but activity increased significantly in mid June, when researchers observed more than 81 million related login attempts and 78 compromised accounts within a two week period. The attackers relied on valid username and password combinations from previous data breaches that had not been changed, making successful login attempts more valuable compared with traditional password guessing techniques.

Password spraying attacks generally involve attackers collecting valid usernames from sources such as company websites, professional networks, leaked databases, and phishing campaigns. After creating a target list, attackers use a limited number of commonly used or previously exposed passwords across multiple accounts rather than attempting many passwords against one account. This approach helps attackers avoid account lockout protections while increasing the possibility of finding accounts with weak or reused credentials. Once access is obtained, attackers can move further into an organization’s environment, potentially leading to business email compromise, data theft, or additional credential harvesting. The LSHIY campaign also involved the abuse of Resource Owner Password Credentials, a legacy OAuth authentication method that has been deprecated in OAuth 2.1. ROPC was originally introduced to help applications transition from direct authentication methods to OAuth based systems, but it does not support modern authentication protections such as multi factor authentication or single sign on. Instead, it sends usernames and passwords directly to the token endpoint without requiring an interactive MFA verification process. Huntress said many affected organizations had implemented MFA through Conditional Access Policies, but those protections did not apply to the specific authentication method used during the attacks.

Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress, explained that although ROPC is described as an authorization method, it can effectively function as an impersonation method. Huntress did not observe additional malicious activity after the successful logins linked to the campaign. Rich Mozeleski, Staff Product Manager at Huntress, suggested that the activity may have been focused on validating credentials for potential resale on underground markets. LSHIY later ended the attacks from the original IP range and confirmed that the infrastructure involved its bring your own IP service. The campaign also highlighted challenges created by IPv6 infrastructure and BYOIP services. These services allow customers to route traffic through providers using their own IP ranges, making it easier for attackers to switch between networks and avoid traditional blocking methods. Huntress said the activity moved from LSHIY controlled IPv6 ranges to FranTech hosted IPv6 ranges and later appeared from 3xK Tech using IPv4 infrastructure. The ability to quickly change providers creates additional difficulties for defenders attempting to block malicious traffic based only on IP addresses.

Huntress analyzed 23 affected businesses and found that eight organizations did not have MFA enabled. Among the remaining 15 organizations, MFA protections did not cover the attacker’s sign in attempts because policies were limited to specific applications, user groups, trusted locations, or remained in report only mode. Researchers said organizations need to review how Conditional Access policies are configured and ensure that authentication protections apply across all users, cloud applications, and client application types. To reduce exposure, Huntress recommended improving password security practices, considering passwordless authentication options, disabling ROPC where possible, restricting Azure CLI access for unnecessary users, and enforcing MFA without exclusions. The company also advised organizations to use stronger Conditional Access settings to prevent authentication methods that cannot satisfy MFA requirements. Huntress emphasized that properly configured identity controls can help prevent attackers from gaining access even when stolen credentials are available.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment