The threat actor will use brute force and password spraying to target multiple accounts until one is successfully compromised. Once in, the threat actor will attempt to gather credentials and other information about the network to sell.
Tag: Iran
Brute Force from Iran to Critical Infrastructure
The threat actors obtain valid user and group email accounts, often through brute force methods like password spraying [T1110.003], to gain initial access to the target’s network.