# T1110.002 Password Cracking

> As of 2026-10-05, T1110.002 (Password Cracking) appears in 22 tracked threats, first reported 2026-05-27 and most recently 2026-10-03, with linked actors including Akira, Salt Typhoon - G1045, Storm-1567; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 22 (14 critical, 6 high, 2 medium)
- **First seen:** 2026-05-27
- **Last seen:** 2026-10-03
- **Threat actors:** 3
- **Detection rules:** 35 (counts only; Blue tier and above)

## Key facts

- **ID:** T1110.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1110
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1110/002/

## Activity timeline

T1110.002 first appeared in tracked threats on 2026-05-27 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 11 reports, and 22 of the 22 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1110.002 Password Cracking is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110). Threadlinqs maps 22 of 2623 tracked threats (0.8%) to it; by severity that is 14 critical, 6 high, 2 medium.

Threats that use T1110.002 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (15 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (10 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (9 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (9 threats), [T1136.001 Local Account](https://intel.threadlinqs.com/technique/T1136.001) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1110.002; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) (1), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1110.002.

- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1110.002, per MITRE ATT&CK.

- Application Log — Application Log Content
- User Account — User Account Authentication

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1

## Tracked threats

22 tracked threats use T1110.002.

- [Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898…](https://intel.threadlinqs.com/threat/TL-2026-2854) — critical — 2026-10-03
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting](https://intel.threadlinqs.com/threat/TL-2026-2174) — high — 2026-08-28
- [China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…](https://intel.threadlinqs.com/threat/TL-2026-1997) — critical — 2026-08-12
- [Coldcard Hardware Wallet $111M Bitcoin Theft: Weak RNG Private Key Vulnerability (Yasmarang PRNG Fallback)](https://intel.threadlinqs.com/threat/TL-2026-1992) — critical — 2026-08-12
- [Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1835) — critical — 2026-08-03
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [CVE-2026-6516: Unauthenticated Remote Code Execution in ManageEngine ADAudit Plus (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1756) — critical — 2026-07-29
- [Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk…](https://intel.threadlinqs.com/threat/TL-2026-1638) — critical — 2026-07-22
- [CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…](https://intel.threadlinqs.com/threat/TL-2026-1568) — high — 2026-07-20
- [wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released](https://intel.threadlinqs.com/threat/TL-2026-1465) — critical — 2026-07-18
- [CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-1464) — critical — 2026-07-17
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…](https://intel.threadlinqs.com/threat/TL-2026-1261) — medium — 2026-07-13
- ['Ill Bloom' Weak-Randomness Vulnerability in Legacy Crypto Wallets Actively Exploited to Drain $3.1M+](https://intel.threadlinqs.com/threat/TL-2026-1170) — critical — 2026-07-10
- [Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…](https://intel.threadlinqs.com/threat/TL-2026-1156) — medium — 2026-07-03
- [FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations](https://intel.threadlinqs.com/threat/TL-2026-1056) — critical — 2026-07-02
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…](https://intel.threadlinqs.com/threat/TL-2026-0882) — high — 2026-06-19
- [Unpatched Windows search: URI Handler NTLMv2 Hash Leak via crumb=location UNC Coercion (No CVE, Microsoft…](https://intel.threadlinqs.com/threat/TL-2026-0673) — high — 2026-06-03
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27

## Related CVEs

CVEs referenced by the tracked threats that use T1110.002, most frequent first.

- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-67649](https://intel.threadlinqs.com/cve/CVE-2025-67649)
- [CVE-2026-57309](https://intel.threadlinqs.com/cve/CVE-2026-57309)
- [CVE-2026-57310](https://intel.threadlinqs.com/cve/CVE-2026-57310)
- [CVE-2026-57311](https://intel.threadlinqs.com/cve/CVE-2026-57311)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-60167](https://intel.threadlinqs.com/cve/CVE-2026-60167)
- [CVE-2026-60168](https://intel.threadlinqs.com/cve/CVE-2026-60168)
- [CVE-2026-60169](https://intel.threadlinqs.com/cve/CVE-2026-60169)
- [CVE-2026-60170](https://intel.threadlinqs.com/cve/CVE-2026-60170)
- [CVE-2026-6516](https://intel.threadlinqs.com/cve/CVE-2026-6516)

## Detection coverage

Threadlinqs maintains 35 detection rules mapped to T1110.002 (SPL 11, KQL 9, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

35 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110) — 175 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1110.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
