# T1110.003 Password Spraying

> As of 2026-10-05, T1110.003 (Password Spraying) appears in 41 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including Akira, Storm-1567, NoName057(16); it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 41 (13 critical, 26 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 25
- **Detection rules:** 92 (counts only; Blue tier and above)

## Key facts

- **ID:** T1110.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1110
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1110/003/

## Activity timeline

T1110.003 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-08 with 12 reports, and 41 of the 41 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1110.003 Password Spraying is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110). Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 13 critical, 26 high, 2 medium.

Threats that use T1110.003 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (23 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (18 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (17 threats), [T1021.002 SMB/Windows Admin Shares](https://intel.threadlinqs.com/technique/T1021.002) (14 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

25 tracked threat actors appear in the threats that use T1110.003; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (3), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (3), [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (2), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (2), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1110.003.

- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)

## Data sources

Telemetry that can reveal T1110.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- User Account — User Account Authentication

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 3
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 3
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 2
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 2
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) — 2
- [APT10](https://intel.threadlinqs.com/actor/APT10) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [FIN7](https://intel.threadlinqs.com/actor/FIN7) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1

## Tracked threats

The 30 most recent of 41 tracked threats that use T1110.003.

- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…](https://intel.threadlinqs.com/threat/TL-2026-2868) — high — 2026-10-03
- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490…](https://intel.threadlinqs.com/threat/TL-2026-2843) — critical — 2026-10-02
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)](https://intel.threadlinqs.com/threat/TL-2026-2793) — high — 2026-09-29
- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…](https://intel.threadlinqs.com/threat/TL-2026-2760) — high — 2026-09-28
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…](https://intel.threadlinqs.com/threat/TL-2026-2514) — high — 2026-09-15
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flow](https://intel.threadlinqs.com/threat/TL-2026-2071) — high — 2026-08-19
- [Suspected China-Linked Actor Runs Near-Autonomous Multi-Agent AI Attack on Taiwan Government, Nuclear Safety…](https://intel.threadlinqs.com/threat/TL-2026-2063) — critical — 2026-08-18
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — high — 2026-08-16
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…](https://intel.threadlinqs.com/threat/TL-2026-2027) — high — 2026-08-16
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13
- [Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defender](https://intel.threadlinqs.com/threat/TL-2026-2062) — high — 2026-08-12
- [Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1904) — critical — 2026-08-05
- [AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…](https://intel.threadlinqs.com/threat/TL-2026-1727) — high — 2026-07-27
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…](https://intel.threadlinqs.com/threat/TL-2026-1342) — high — 2026-07-14
- [Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…](https://intel.threadlinqs.com/threat/TL-2026-1286) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…](https://intel.threadlinqs.com/threat/TL-2026-0882) — high — 2026-06-19

## Related CVEs

CVEs referenced by the tracked threats that use T1110.003, most frequent first.

- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)

## Detection coverage

Threadlinqs maintains 92 detection rules mapped to T1110.003 (SPL 31, KQL 39, Sigma 21, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

92 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110) — 175 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1110.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
