# T1110.004 Credential Stuffing

> As of 2026-10-05, T1110.004 (Credential Stuffing) appears in 33 tracked threats, first reported 2026-02-25 and most recently 2026-09-29, with linked actors including Cavern Manticore, ShinyHunters, UNK_OutFlareAZ; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 33 (9 critical, 20 high, 4 medium)
- **First seen:** 2026-02-25
- **Last seen:** 2026-09-29
- **Threat actors:** 12
- **Detection rules:** 84 (counts only; Blue tier and above)

## Key facts

- **ID:** T1110.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1110
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1110/004/

## Activity timeline

T1110.004 first appeared in tracked threats on 2026-02-25 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 15 reports, and 33 of the 33 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1110.004 Credential Stuffing is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110). Threadlinqs maps 33 of 2623 tracked threats (1.3%) to it; by severity that is 9 critical, 20 high, 4 medium.

Threats that use T1110.004 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (18 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (14 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (14 threats), [T1133 External Remote Services](https://intel.threadlinqs.com/technique/T1133) (13 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

12 tracked threat actors appear in the threats that use T1110.004; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2), [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) (2), [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1110.004.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)

## Data sources

Telemetry that can reveal T1110.004, per MITRE ATT&CK.

- Application Log — Application Log Content
- User Account — User Account Authentication

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 1
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 1
- [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) — 1
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1
- [UNK_pyreq2323](https://intel.threadlinqs.com/actor/UNK_pyreq2323) — 1
- [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) — 1

## Tracked threats

The 30 most recent of 33 tracked threats that use T1110.004.

- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…](https://intel.threadlinqs.com/threat/TL-2026-2566) — high — 2026-09-18
- [TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentials](https://intel.threadlinqs.com/threat/TL-2026-2491) — medium — 2026-09-14
- [OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…](https://intel.threadlinqs.com/threat/TL-2026-2476) — high — 2026-09-13
- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — high — 2026-09-12
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence](https://intel.threadlinqs.com/threat/TL-2026-1825) — high — 2026-08-03
- [Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809…](https://intel.threadlinqs.com/threat/TL-2026-1705) — critical — 2026-07-26
- [Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data](https://intel.threadlinqs.com/threat/TL-2026-1654) — high — 2026-07-23
- [CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine…](https://intel.threadlinqs.com/threat/TL-2026-1627) — critical — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1580) — high — 2026-07-20
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released](https://intel.threadlinqs.com/threat/TL-2026-1465) — critical — 2026-07-18
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…](https://intel.threadlinqs.com/threat/TL-2026-1390) — critical — 2026-07-15
- ["Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign](https://intel.threadlinqs.com/threat/TL-2026-1356) — high — 2026-07-15
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…](https://intel.threadlinqs.com/threat/TL-2026-1342) — high — 2026-07-14
- [AI-Jailbreak-Enabled C2 Automation: "bandcampro" Used Jailbroken Gemini to Build and Run Botnet in Patriot…](https://intel.threadlinqs.com/threat/TL-2026-1308) — high — 2026-07-14
- [ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations](https://intel.threadlinqs.com/threat/TL-2026-1275) — high — 2026-07-13
- [BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1060) — high — 2026-07-02
- [FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations](https://intel.threadlinqs.com/threat/TL-2026-1056) — critical — 2026-07-02
- [Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign](https://intel.threadlinqs.com/threat/TL-2026-0984) — critical — 2026-06-28
- [FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…](https://intel.threadlinqs.com/threat/TL-2026-0927) — critical — 2026-06-24
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…](https://intel.threadlinqs.com/threat/TL-2026-0882) — high — 2026-06-19
- [ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…](https://intel.threadlinqs.com/threat/TL-2026-0817) — high — 2026-06-16
- [GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com…](https://intel.threadlinqs.com/threat/TL-2026-0704) — high — 2026-06-07
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)](https://intel.threadlinqs.com/threat/TL-2026-0531) — high — 2026-05-19
- [The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB…](https://intel.threadlinqs.com/threat/TL-2026-2115) — medium — 2026-05-13

## Related CVEs

CVEs referenced by the tracked threats that use T1110.004, most frequent first.

- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2026-11374](https://intel.threadlinqs.com/cve/CVE-2026-11374)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-6973](https://intel.threadlinqs.com/cve/CVE-2026-6973)

## Detection coverage

Threadlinqs maintains 84 detection rules mapped to T1110.004 (SPL 38, KQL 26, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.

84 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1110 Brute Force](https://intel.threadlinqs.com/technique/T1110) — 175 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1110.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
