# Huntress Investigates Ongoing Password-Spraying Attacks Against Microsoft Azure CLI

DevFeed: [Huntress Investigates Ongoing Password-Spraying Attacks Against Microsoft Azure CLI](<https://devfeed.tech/articles/no-bad-cap-inside-an-ongoing-lshiy-password-spray-attack-54463.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/lshiy-password-spray-attack>)

Author: Lindsey O'Donnell-Welch; Andrew Brandt; Rich Mozeleski

Published: 2026-06-30T20:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [password spraying](<https://devfeed.tech/topics/password-spraying.md>), [Copilot in Azure](<https://devfeed.tech/topics/copilot-in-azure.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [bulletproof-hosting](<https://devfeed.tech/tags/bulletproof-hosting.md>), [cli](<https://devfeed.tech/tags/cli.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Huntress investigates an ongoing password-spraying campaign targeting Microsoft Azure CLI logins. The attackers shifted between hosting providers and used large IP ranges, including a low-and-slow IPv4 approach, to sustain high login-attempt volumes while attempting to evade detection.

## Source excerpt

Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.