# T1110 Brute Force

> As of 2026-10-05, T1110 (Brute Force) appears in 175 tracked threats, first reported 2026-01-25 and most recently 2026-10-03, with linked actors including MuddyWater, Static Tundra, APT28; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 175 (63 critical, 86 high, 22 medium, 1 low)
- **First seen:** 2026-01-25
- **Last seen:** 2026-10-03
- **Threat actors:** 82
- **Detection rules:** 99 (counts only; Blue tier and above)

## Key facts

- **ID:** T1110
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1110/

## Activity timeline

T1110 first appeared in tracked threats on 2026-01-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 68 reports, and 175 of the 175 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1110 Brute Force is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 175 of 2623 tracked threats (6.7%) to it; by severity that is 63 critical, 86 high, 22 medium, 1 low.

Threats that use T1110 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (123 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (110 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (96 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (90 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (81 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

82 tracked threat actors appear in the threats that use T1110; the most frequent are [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (6), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (6), [APT28](https://intel.threadlinqs.com/actor/APT28) (5), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (5), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (5).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1110.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)

## Data sources

Telemetry that can reveal T1110, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- User Account — User Account Authentication

## Threat actors using it

- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 6
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 6
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 5
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 5
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 5
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 4
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 4
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 3

## Tracked threats

The 30 most recent of 175 tracked threats that use T1110.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…](https://intel.threadlinqs.com/threat/TL-2026-2079) — critical — 2026-08-20
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — critical — 2026-08-19
- [Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay](https://intel.threadlinqs.com/threat/TL-2026-2053) — high — 2026-08-17
- [Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…](https://intel.threadlinqs.com/threat/TL-2026-2047) — medium — 2026-08-17
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…](https://intel.threadlinqs.com/threat/TL-2026-2031) — high — 2026-08-16
- [AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…](https://intel.threadlinqs.com/threat/TL-2026-1963) — high — 2026-08-09
- [City of Coweta, Oklahoma Hit by Anubis Ransomware Attack](https://intel.threadlinqs.com/threat/TL-2026-1948) — high — 2026-08-09
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…](https://intel.threadlinqs.com/threat/TL-2026-1868) — high — 2026-08-04
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…](https://intel.threadlinqs.com/threat/TL-2026-1824) — medium — 2026-08-02
- [SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Records](https://intel.threadlinqs.com/threat/TL-2026-1823) — high — 2026-08-02
- [Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500…](https://intel.threadlinqs.com/threat/TL-2026-1819) — medium — 2026-08-02
- [Anthropic AI Agent Publishes Live Credential-Stealing Malware as PyPI Package "anthropickit"](https://intel.threadlinqs.com/threat/TL-2026-1801) — high — 2026-07-31
- [CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PII](https://intel.threadlinqs.com/threat/TL-2026-1796) — medium — 2026-07-31
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — high — 2026-07-31
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…](https://intel.threadlinqs.com/threat/TL-2026-1780) — critical — 2026-07-31
- [SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims](https://intel.threadlinqs.com/threat/TL-2026-1815) — high — 2026-07-29
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — medium — 2026-07-27
- [Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC](https://intel.threadlinqs.com/threat/TL-2026-1730) — 2026-07-27
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkit](https://intel.threadlinqs.com/threat/TL-2026-1754) — high — 2026-07-25

## Related CVEs

CVEs referenced by the tracked threats that use T1110, most frequent first.

- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)

## Detection coverage

Threadlinqs maintains 99 detection rules mapped to T1110 (SPL 30, KQL 41, Sigma 28). Rule content is available to Blue tier accounts and above; this page shows counts only.

99 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1110.001 Password Guessing](https://intel.threadlinqs.com/technique/T1110.001) — 36 tracked threats
- [T1110.002 Password Cracking](https://intel.threadlinqs.com/technique/T1110.002) — 22 tracked threats
- [T1110.003 Password Spraying](https://intel.threadlinqs.com/technique/T1110.003) — 41 tracked threats
- [T1110.004 Credential Stuffing](https://intel.threadlinqs.com/technique/T1110.004) — 33 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1110
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
