{
  "id": 2055509,
  "title": "LSHIY: Large-Scale Password Spraying Abusing ROPC and IPv6",
  "url": "https://urgent.news/2026/08/20/lshiy-large-scale-password-spraying-abusing-ropc-and-ipv6",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T01:20:55.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/lshiy-large-scale-password-spraying-abusing-ropc-and-ipv6-26cb"
  },
  "original_language": "en",
  "account": "The article details a large-scale password spraying attack called LSHIY that exploited Microsoft Azure's OAuth ROPC (Resource Owner Password Credentials) grant. Attackers abused this grant to try a small set of reused passwords against many accounts, circumventing the need for multi-factor authentication (MFA). This allowed them to obtain tokens from compromised accounts, even when MFA was enabled, as the policy had coverage limitations. The attackers used IP spoofing techniques involving large IPv6 ranges to evade detection. Over two weeks, they conducted over 81 million authentication attempts, compromising around 78 accounts. No post-success activities were observed, indicating potential credential harvesting, lateral movement, or data theft. The attack leveraged Azure CLI and BYOIP (Bring Your Own IP) methods, connecting to Azure's token endpoint from external infrastructure like LSHIY LLC, FranTech, and Tor. Visibility for victims was limited, as MFA prompts were not displayed. Administrators might notice a small number of successful logins among numerous failures. The success conditions included valid reused passwords, ROPC usage, and lack of comprehensive Conditional Access coverage. Failure conditions involved disabling ROPC, blocking non-interactive authentication flows, and implementing stricter Azure CLI access controls. The primary evidence of the attack lies in Azure Identity Provider (IdP) logs, specifically focusing on Azure CLI non-interactive sign-ins, suspicious patterns from IPv6 prefixes, and conditional access reports with exclusions or failures.",
  "summary": "LSHIY: Large-Scale Password Spraying Abusing ROPC and IPv6 1. Basic Information Article Title : How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant Publisher : Huntress Publish Date : 2026-08-19 Severity : High Original Source : Huntress Related Sources : BleepingComputer Related Entities : LSHIY campaign, Microsoft Azure CLI, Entra ID, OAuth ROPC, Conditional Access, IPv6 BYOIP 2.…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}