Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
Brute forcing credentials may take place at various points during a breach. For example, adversaries may attempt to brute force access to Valid Accounts within a victim environment leveraging knowledge gathered from other post-compromise behaviors such as OS Credential Dumping, Account Discovery, or Password Policy Discovery. Adversaries may also combine brute forcing activity with behaviors such as External Remote Services as part of Initial Access.
If an adversary guesses the correct password but fails to login to a compromised account due to location-based conditional access policies, they may change their infrastructure until they match the victim’s location and therefore bypass those policies.
Rules on DetectionCode tagged with T1110 or one of its sub-techniques.
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius engaged in various brute forcing activities via SMB in victim environments. |
| GroupAPT28 | APT28 can perform brute force attacks to obtain credentials. |
| GroupAPT38 | APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable. |
| GroupAPT39 | APT39 has used Ncrack to reveal credentials. |
| GroupAPT41 | APT41 performed password brute-force attacks on the local admin account. |
| GroupDarkVishnya | DarkVishnya used brute-force attack to obtain login data. |
| GroupDragonfly | Dragonfly has attempted to brute force credentials to gain access. |
| GroupEmber Bear | Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command. |
| Used by | Procedure example |
|---|---|
| MalwareCaterpillar WebShell | Caterpillar WebShell has a module to perform brute force attacks on a system. |
| MalwareChaos | Chaos conducts brute force attacks against SSH services to gain initial access. |
| ToolCrackMapExec | CrackMapExec can brute force supplied user credentials across a network range. |
| MalwareKinsing | Kinsing has attempted to brute force hosts over SSH. |
| ToolPoshC2 | PoshC2 has modules for brute forcing local administrator and AD user accounts. |
| MalwarePysa | Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts. |
| MalwareQakBot | QakBot can conduct brute force attacks to capture credentials. |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.