Ans. Brute force targets one account with many passwords. Spraying targets many accounts with a few common passwords, specifically to stay below lockout thresholds.
Timing Is Everything: How Attackers Disguise Password Spraying Attacks
Authentication log showing repeated failed login entries across multiple user accounts
One failed login at 09:14. Account exists, password wrong, no lockout.
In a large environment, there are such things which occur so often that it is genuinely difficult to separate these from someone whos caps lock was left on, and that is exactly the point.
See, Password spraying works because the attack was never in innocent individual attempts, but it actually lived in the spacing between these attempts.
This is how that spacing gets engineered, what the published incident reports actually describe, and why threshold-based detection keeps missing it.
What Is the Structure Of the Attack
There are mainly two types of attacks: Brute force and Password spraying. While Brute force goes deep on only one account, password spraying occurs across multiple accounts and goes wide.
This distinction is essentially of high importance because lockout policies are designed to catch depth. An account that sees ten failures in two minutes gets locked.
An account with failures occurring in between sufficient time gaps like on the mornings of two different days, say monday and tuesday see no lockout as such, which is the exact behaviour a spray is built to produce.
Targets follow the same logic. Since VPN portals, Citrix gateways, RDP gateways, and Entra ID tenants all are connected to a public internet and have authentication procedures against the same directory, so only a weak password throughout that population is reasonable.
The Lockout Policy Is Their Specification
Here is the part that deserves more attention than it gets.
Whenever an account goes through a lockout threshold, it is documented, and any attacker who has read the material even once would know the shape of the constraint before he even starts the work. These can appear in guides related to vendor hardening, compliance baselines, and documents of the computer regarding all the internal policies.
Even when you set the threshold to the lowest failure, the attacker doesn’t stop. Instead, it tells the attacker as to exactly how many chances he/she has left; for example, if you set the threshold at five failures, the attacker only attempts four. So the defensive configuration does not stop the attack.
This is why threshold-based detection is structurally compromised rather than merely imperfect. It is a published rule that the adversary optimizes against, and treating it as a detection control confuses a speed limit with a roadblock.
The Disguises That Actually Work
There are four techniques marked across most documented campaigns and neither one of them are sophisticated.
Slowing the Clock
A lot of attack attempts are scattered over a longer duration of time like days or weeks, which is exactly what the threat group Midnight Blizzard did as stated by Microsoft. They did this to avoid detection by using the low frequencies generated during attempts.
Spreading the Source
When a single source of IP is responsible for running thousands of attempts, its chances of being detected are more in comparison to when that IP source is distributed. Microsoft reported that for acquiring its credential databases, STRONTIUM used a large pool of addresses including Tor anonymizers, and the operators working for the threat group Midnight Blizzard used proxy networks of the residential areas so that the attack is put inside addresses that look like ordinary home broadband. This way suspicion is avoided and the work becomes ten times easy.
Choosing the Quiet Door
Production environments are an active system in an organization which stores all of its important data. These environments are heavily guarded but non-production tenants made ‘just for testing’ are often easily forgotten. Midnight blizzard used exactly this carelessness to breach into the database using simple password spraying on the non-production test tenant which had no Multi Factor Authentication (MFA) integrated in it.
Blending Into the Calendar
These attackers track patterns and frequencies of the network so that when the network is already busy, a few attempts can be conducted without anyone noticing. Monday at nine in the morning is the busiest and a few extra failures made during that time is worth more than a perfect stealth at say three in the morning.
What the Incident Reports Actually Describe
Since a lot of these campaigns were recorded by the vendors who actually got hit, the public record is good.
Microsoft also reported that a non-production test tenant that didn’t have MFA was compromised by the Midnight Blizzard on 25 January 2024, which then turned to a legacy OAuth application with high privileges so that it could reach the corporate environment. The spray was on the front door. The OAuth app was the actual prize.
Talos Intelligence documented an attack conducted by the Play Ransomware Group against the Active Directory accounts of the corporate sector. Once they managed to breach this using password spraying, they elevated their status using internal exploit tools and disabled the entire security system at once.
Microsoft released a report on September 2023 regarding the cyber espionage carried out by the state sponsored threat group Peach Sandstorm. The report mentioned how the group used spraying on the Entra ID accounts based in the defense and medical sector.
And the 2019 Citrix breach, where attackers were believed to have accessed internal documents over a period of months, is generally cited as a spraying case. Months. That is the detection gap this technique creates.
Why “Just Turn On MFA” Isn’t Finished
Multi Factor Authentication or MFA is the most effective mechanism when it comes to attack control. This should be installed everywhere.
Talos recorded how the Play Group bypassed MFA through social engineering help desks. See MFA is only as secure as its process so when MFA requires a secondary token, these attackers simply call the company’s help desk pretending to be an employee. The person at the help desk then gives out all the information without checking the accuracy of the caller’s ID. and this is how the encryption wall of MFA remained secure but the attackers still bypassed it.
Any environment serious about this needs to treat help desk verification as part of the authentication perimeter, because attackers already do.
What Detection Has to Watch Instead
Counting failures per account misses the pattern by design.
Individual events often look harmless but when these are clubbed together to view the data, the true threat is much more obvious. For example a single password used across a vast population of many accounts seeing failure during a short span of time
That requires centralized logging across every internet-facing system tied to the directory, which is unglamorous infrastructure work and the reason so many organizations skip it.
Final Analysis
Password spraying is still used largely today because it is cheap and works against the most easy safety net: a poorly designed and easy to guess password.
The most shocking part isn’t the relative easiness of the attack, it is that most of the organizations who have been a victim of such attacks have security teams, budgets and even policies in place. That’s why it isn’t really a security problem, it’s a seriousness problem. Midnight Blizzard got in through a test tenant nobody had thought about in years.
Which suggests the most useful question is not whether the lockout policy is tuned correctly. The most helpful insight would be to know about the number of authentication endpoints that exist which no one has paid attention to since the person responsible for building them left.
Frequently Asked Questions
What are the key differences between password spraying and using brute force?
Does account lockout stop password spraying?
Ans. No. Lockout thresholds are published and attackers simply stay beneath them, which makes the policy a rate limit rather than a defense.
Is MFA enough on its own?
Ans. It is the strongest single control but not complete. Documented attacks have bypassed it by social-engineering help desks into enrolling attacker-controlled devices.
What is the most commonly missed exposure?
Ans. Forgotten internet-facing systems and unused tenants. Several major intrusions began at an endpoint the organization had stopped thinking about.
One convincing email can be sufficient to pose major problems regarding security for a business. An email that appears to…
A client intake form works best for collecting data like names, contact information, and project needs. But what does a…
Salesforce consulting firm was not something that is too difficult to choose. But nowadays, there are too many options available…
Protecting employees’ data from when they get hired and get their first laptop to the day the laptop finally gets…
ALT: Recovering lost access to a profile IMG SRC: https://www.howtogeek.com/microsoft-excel-ways-to-recover-lost-work/ Losing access to an old online profile can be frustrating,…
Choosing the best identity verification software is a high-stakes decision for any business that verifies customers remotely, identity documents, facial…
Personal injury cases deal with a lot of information, ranging from medical records and accident reports to insurance documents and…
Nowadays, there is a lot of data say it in laptops, phones, cloud platforms, messaging tools, and in AI-powered applications.…
Ransomeware used to be random. Attackers sent out mass emails and just waited to see who clicked, but that’s not…









