# T1110.001 Password Guessing

> As of 2026-10-05, T1110.001 (Password Guessing) appears in 36 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including Akira, FSB Center 16, FortiBleed operator; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 36 (7 critical, 20 high, 9 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-04
- **Threat actors:** 14
- **Detection rules:** 77 (counts only; Blue tier and above)

## Key facts

- **ID:** T1110.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1110
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1110/001/

## Activity timeline

T1110.001 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 14 reports, and 36 of the 36 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1110.001 Password Guessing is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110). Threadlinqs maps 36 of 2623 tracked threats (1.4%) to it; by severity that is 7 critical, 20 high, 9 medium.

Threats that use T1110.001 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (19 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (17 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (15 threats), [T1133 External Remote Services](https://intel.threadlinqs.com/technique/T1133) (15 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

14 tracked threat actors appear in the threats that use T1110.001; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (1), [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) (1), [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (1), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1110.001.

- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1110.001, per MITRE ATT&CK.

- Application Log — Application Log Content
- User Account — User Account Authentication

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 1
- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 1
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 1
- [N](https://intel.threadlinqs.com/actor/N) — 1
- [SNOWLIGHT](https://intel.threadlinqs.com/actor/SNOWLIGHT) — 1
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1
- [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) — 1
- [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) — 1

## Tracked threats

The 30 most recent of 36 tracked threats that use T1110.001.

- [Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board…](https://intel.threadlinqs.com/threat/TL-2026-2898) — high — 2026-10-04
- [Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation](https://intel.threadlinqs.com/threat/TL-2026-2607) — medium — 2026-09-21
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flow](https://intel.threadlinqs.com/threat/TL-2026-2071) — high — 2026-08-19
- [Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flaw](https://intel.threadlinqs.com/threat/TL-2026-1965) — medium — 2026-08-10
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1584) — high — 2026-07-21
- [Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1580) — high — 2026-07-20
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…](https://intel.threadlinqs.com/threat/TL-2026-1394) — medium — 2026-07-16
- ["Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign](https://intel.threadlinqs.com/threat/TL-2026-1356) — high — 2026-07-15
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…](https://intel.threadlinqs.com/threat/TL-2026-1342) — high — 2026-07-14
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…](https://intel.threadlinqs.com/threat/TL-2026-1290) — medium — 2026-07-14
- [NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…](https://intel.threadlinqs.com/threat/TL-2026-1279) — critical — 2026-07-13
- [WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage…](https://intel.threadlinqs.com/threat/TL-2026-1180) — high — 2026-07-10
- [JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack](https://intel.threadlinqs.com/threat/TL-2026-1117) — critical — 2026-07-05
- [Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…](https://intel.threadlinqs.com/threat/TL-2026-1156) — medium — 2026-07-03
- [JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248)…](https://intel.threadlinqs.com/threat/TL-2026-1044) — critical — 2026-07-01
- [FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…](https://intel.threadlinqs.com/threat/TL-2026-0927) — critical — 2026-06-24
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…](https://intel.threadlinqs.com/threat/TL-2026-0882) — high — 2026-06-19
- [Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer](https://intel.threadlinqs.com/threat/TL-2026-1245) — medium — 2026-06-15
- [Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…](https://intel.threadlinqs.com/threat/TL-2026-0809) — high — 2026-06-15
- [Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan…](https://intel.threadlinqs.com/threat/TL-2026-0705) — high — 2026-06-07
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)](https://intel.threadlinqs.com/threat/TL-2026-0531) — high — 2026-05-19
- [CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)](https://intel.threadlinqs.com/threat/TL-2026-0386) — high — 2026-04-17

## Related CVEs

CVEs referenced by the tracked threats that use T1110.001, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-28000](https://intel.threadlinqs.com/cve/CVE-2024-28000)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-7443](https://intel.threadlinqs.com/cve/CVE-2025-7443)
- [CVE-2026-1969](https://intel.threadlinqs.com/cve/CVE-2026-1969)
- [CVE-2026-34197](https://intel.threadlinqs.com/cve/CVE-2026-34197)
- [CVE-2026-3844](https://intel.threadlinqs.com/cve/CVE-2026-3844)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-48907](https://intel.threadlinqs.com/cve/CVE-2026-48907)
- [CVE-2026-6433](https://intel.threadlinqs.com/cve/CVE-2026-6433)

## Detection coverage

Threadlinqs maintains 77 detection rules mapped to T1110.001 (SPL 31, KQL 29, Sigma 15, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

77 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110) — 175 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1110.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
