Activity timeline
T1110.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 33 of the 33 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1110.004 Credential Stuffing is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1110 Brute Force. Threadlinqs maps 33 of 2623 tracked threats (1.3%) to it; by severity that is 9 critical, 20 high, 4 medium.
Threats that use T1110.004 most often also use T1078 Valid Accounts (18 threats), T1190 Exploit Public-Facing Application (14 threats), T1213 Data from Information Repositories (14 threats), T1133 External Remote Services (13 threats), T1071.001 Web Protocols (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
12 tracked threat actors appear in the threats that use T1110.004; the most frequent are Cavern Manticore (2), ShinyHunters (2), UNK_OutFlareAZ (2), Akira (1), EvilTokens (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1110.004.
Data sources
Telemetry that can reveal T1110.004, per MITRE ATT&CK.
- Application Log — Application Log Content
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 33 tracked threats that use T1110.004.
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…high
- TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentialsmedium
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…high
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capabilityhigh
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Executioncritical
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligencehigh
- Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809…critical
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Datahigh
- CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine…critical
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Releasedcritical
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…critical
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaignhigh
- OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…high
- AI-Jailbreak-Enabled C2 Automation: "bandcampro" Used Jailbroken Gemini to Build and Run Botnet in Patriot…high
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrationshigh
- BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…high
- FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operationscritical
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaigncritical
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…critical
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…high
- ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…high
- GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com…high
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)high
- The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB…medium
Detection coverage
Threadlinqs maintains 84 detection rules mapped to T1110.004 (SPL 38, KQL 26, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1110 Brute Force — 175 tracked threats at the technique level.