Activity timeline
T1110 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 68 reports, and 175 of the 175 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1110 Brute Force is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 175 of 2623 tracked threats (6.7%) to it; by severity that is 63 critical, 86 high, 22 medium, 1 low.
Threats that use T1110 most often also use T1078 Valid Accounts (123 threats), T1190 Exploit Public-Facing Application (110 threats), T1059 Command and Scripting Interpreter (96 threats), T1071 Application Layer Protocol (90 threats), T1027 Obfuscated Files or Information (81 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
82 tracked threat actors appear in the threats that use T1110; the most frequent are MuddyWater (6), Static Tundra (6), APT28 (5), Sandworm (5), ShinyHunters (5).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1110.
Data sources
Telemetry that can reveal T1110, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 175 tracked threats that use T1110.
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…high
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relayhigh
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…medium
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…high
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…high
- City of Coweta, Oklahoma Hit by Anubis Ransomware Attackhigh
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…high
- Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…high
- Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addressescritical
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…medium
- SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Recordshigh
- Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500…medium
- Anthropic AI Agent Publishes Live Credential-Stealing Malware as PyPI Package "anthropickit"high
- CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PIImedium
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeyshigh
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Thefthigh
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claimshigh
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Processhigh
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Accessmedium
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkithigh
Detection coverage
Threadlinqs maintains 99 detection rules mapped to T1110 (SPL 30, KQL 41, Sigma 28). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1110.001 Password Guessing — 36 tracked threats
- T1110.002 Password Cracking — 22 tracked threats
- T1110.003 Password Spraying — 41 tracked threats
- T1110.004 Credential Stuffing — 33 tracked threats