Password Spraying

T1110.003

Sub-technique of T1110 Brute Force.View on attack.mitre.org

About this technique

Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.

Typically, management services over commonly used ports are used when password spraying. Commonly targeted services include the following:

* SSH (22/TCP)
* Telnet (23/TCP)
* FTP (21/TCP)
* NetBIOS / SMB / Samba (139/TCP & 445/TCP)
* LDAP (389/TCP)
* Kerberos (88/TCP)
* RDP / Terminal Services (3389/TCP)
* HTTP/HTTP Management Services (80/TCP & 443/TCP)
* MSSQL (1433/TCP)
* Oracle (1521/TCP)
* MySQL (3306/TCP)
* VNC (5900/TCP)

In addition to management services, adversaries may "target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols," as well as externally facing email applications, such as Office 365.

In order to avoid detection thresholds, adversaries may deliberately throttle password spraying attempts to avoid triggering security alerting. Additionally, adversaries may leverage LDAP and Kerberos authentication attempts, which are less likely to trigger high-visibility events such as Windows "logon failure" event ID 4625 that is commonly triggered by failed SMB connection attempts.

Detection rules42

Rules on DetectionCode tagged with T1110.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk42

RuleTypeRiskData source
AWS High Number Of Failed Authentications From IpAnomalyNULLAWS CloudTrail ConsoleLogin
AWS Multiple Users Failing To Authenticate From IpAnomalyNULLAWS CloudTrail ConsoleLogin
AWS Unusual Number of Failed Authentications From IpAnomalyNULLAWS CloudTrail ConsoleLogin
Azure Active Directory High Risk Sign-inTTPNULLAzure Active Directory
Azure AD High Number Of Failed Authentications From IpTTPNULLAzure Active Directory
Azure AD Multi-Source Failed Authentications SpikeHuntingNULLAzure Active Directory
Azure AD Multiple Users Failing To Authenticate From IpAnomalyNULLAzure Active Directory
Azure AD Successful Authentication From Different IpsTTPNULLAzure Active Directory
Azure AD Unusual Number of Failed Authentications From IpAnomalyNULLAzure Active Directory
Cisco ASA - User Account Lockout Threshold ExceededAnomalyNULLCisco ASA Logs
Detect Distributed Password Spray AttemptsHuntingNULLAzure Active Directory Sign-in activity
Detect Password Spray Attack Behavior From SourceTTPNULLWindows Event Log Security 4624, Windows Event Log Security 4625
Detect Password Spray Attack Behavior On UserTTPNULLWindows Event Log Security 4624, Windows Event Log Security 4625
Detect Password Spray AttemptsTTPNULLWindows Event Log Security 4625
GCP Multiple Users Failing To Authenticate From IpAnomalyNULLGoogle Workspace

Groups11

Software4

Campaigns2

Procedure examples17

Groups11

Used byProcedure example
GroupAgrius

Agrius engaged in password spraying via SMB in victim environments.

GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks.

GroupAPT29

APT29 has conducted brute force password spray attacks.

GroupAPT33

APT33 has used password spraying to gain access to target systems.

GroupChimera

Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts.

GroupEmber Bear

Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords.

GroupHAFNIUM

HAFNIUM has gained initial access through password spray attacks.

GroupHEXANE

HEXANE has used password spraying attacks to obtain valid credentials.

View all 11 groups examples

Software4

Used byProcedure example
MalwareBad Rabbit

Bad Rabbit’s infpub.dat file uses NTLM login credentials to brute force Windows machines.

ToolCrackMapExec

CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password.

MalwareLinux Rabbit

Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server.

ToolMailSniper

MailSniper can be used for password spraying against Exchange and Office 365.

Campaigns2

Used byProcedure example
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials.

CampaignQuad7 Activity

Quad7 Activity has conducted a throttled variant of password spraying techniques that only utilized a single attempt to sign in within a 24-hour time period, eluding brute force detection thresholds.

References3

  1. BlackHillsInfosec Password Spraying Open source
    Thyer, J. (2015, October 30). Password Spraying & Other Fun with RPCCLIENT. Retrieved April 25, 2017.
  2. Microsoft Storm-0940 Open source
    Microsoft Threat Intelligence. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. Retrieved June 4, 2025.
  3. US-CERT TA18-068A 2018 Open source
    US-CERT. (2018, March 27). TA18-068A Brute Force Attacks Conducted by Cyber Actors. Retrieved October 2, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.