Activity timeline
T1110.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 36 of the 36 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1110.001 Password Guessing is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1110 Brute Force. Threadlinqs maps 36 of 2623 tracked threats (1.4%) to it; by severity that is 7 critical, 20 high, 9 medium.
Threats that use T1110.001 most often also use T1190 Exploit Public-Facing Application (19 threats), T1078 Valid Accounts (17 threats), T1046 Network Service Discovery (15 threats), T1133 External Remote Services (15 threats), T1071.001 Web Protocols (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1110.001; the most frequent are Akira (1), FSB Center 16 (1), FortiBleed operator (1), GhostEmperor (1), JADEPUFFER (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1110.001.
Data sources
Telemetry that can reveal T1110.001, per MITRE ATT&CK.
- Application Log — Application Log Content
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 36 tracked threats that use T1110.001.
- Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board…high
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluationmedium
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flowhigh
- Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flawmedium
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…high
- Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…high
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…medium
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaignhigh
- OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…high
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…high
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…medium
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…critical
- WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage…high
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attackcritical
- Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…medium
- JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248)…critical
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…critical
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…high
- Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailermedium
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan…high
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)high
- CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)high
Detection coverage
Threadlinqs maintains 77 detection rules mapped to T1110.001 (SPL 31, KQL 29, Sigma 15, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1110 Brute Force — 175 tracked threats at the technique level.