Timing Is Everything: How Attackers Disguise Password Spraying Attacks

Mr Kumar
Reviewed By :
Mr Kumar
Saipansab Nadaf Written by Saipansab Nadaf
Updated on
Jul 17, 2026

Authentication log showing repeated failed login entries across multiple user accounts


One failed login at 09:14. Account exists, password wrong, no lockout.

In a large environment, there are such things which occur so often that it is genuinely difficult to separate these from someone whos caps lock was left on, and that is exactly the point.

See, Password spraying works because the attack was never in innocent individual attempts, but it actually lived in the spacing between these attempts. 

This is how that spacing gets engineered, what the published incident reports actually describe, and why threshold-based detection keeps missing it.


What Is the Structure Of the Attack

There are mainly two types of attacks: Brute force and Password spraying. While Brute force goes deep on only one account, password spraying occurs across multiple accounts and goes wide. 

This distinction is essentially of high importance because lockout policies are designed to catch depth. An account that sees ten failures in two minutes gets locked. 

An account with failures occurring in between sufficient time gaps like on the mornings of two different days, say monday and tuesday see no lockout as such, which is the exact behaviour a spray is built to produce. 

Targets follow the same logic. Since VPN portals, Citrix gateways, RDP gateways, and Entra ID tenants all are connected to a public internet and have authentication procedures against the same directory, so only a weak password throughout that population is reasonable.  

The Lockout Policy Is Their Specification

Here is the part that deserves more attention than it gets.

Whenever an account goes through a lockout threshold, it is documented, and any attacker who has read the material even once would know the shape of the constraint before he even starts the work. These can appear in guides related to vendor hardening, compliance baselines, and documents of the computer regarding all the internal policies. 

Even when you set the threshold to the lowest failure, the attacker doesn’t stop. Instead, it tells the attacker as to exactly how many chances he/she has left; for example, if you set the threshold at five failures, the attacker only attempts four. So the defensive configuration does not stop the attack. 

This is why threshold-based detection is structurally compromised rather than merely imperfect. It is a published rule that the adversary optimizes against, and treating it as a detection control confuses a speed limit with a roadblock.

The Disguises That Actually Work

There are four techniques marked across most documented campaigns and neither one of them are sophisticated.

Slowing the Clock

A lot of attack attempts are scattered over a longer duration of time like days or weeks, which is exactly what the threat group Midnight Blizzard did as stated by Microsoft. They did this to avoid detection by using the low frequencies generated during attempts. 

Spreading the Source

When a single source of IP is responsible for running thousands of attempts, its chances of being detected are more in comparison to when that IP source is distributed. Microsoft reported that for acquiring its credential databases, STRONTIUM used a large pool of addresses including Tor anonymizers, and the operators working for the threat group Midnight Blizzard used proxy networks of the residential areas so that the attack is put inside addresses that look like ordinary home broadband. This way suspicion is avoided and the work becomes ten times easy.  

Choosing the Quiet Door

Production environments are an active system in an organization which stores all of its important data. These environments are heavily guarded but non-production tenants made ‘just for testing’ are often easily forgotten. Midnight blizzard used exactly this carelessness to breach into the database using simple password spraying on the non-production test tenant which had no Multi Factor Authentication (MFA) integrated in it. 

Blending Into the Calendar

These attackers track patterns and frequencies of the network so that when the network is already busy, a few attempts can be conducted without anyone noticing. Monday at nine in the morning is the busiest and a few extra failures made during that time is worth more than a perfect stealth at say three in the morning. 

What the Incident Reports Actually Describe

Since a lot of these campaigns were recorded by the vendors who actually got hit, the public record is good. 

Microsoft also reported that a non-production test tenant that didn’t have MFA was compromised by the Midnight Blizzard on 25 January 2024, which then turned to a legacy OAuth application with high privileges so that it could reach the corporate environment. The spray was on the front door. The OAuth app was the actual prize.

Talos Intelligence documented an attack conducted by the Play Ransomware Group against the Active Directory accounts of the corporate sector. Once they managed to breach this using password spraying, they elevated their status using internal exploit tools and disabled the entire security system at once. 

Microsoft released a report on September 2023 regarding the cyber espionage carried out by the state sponsored threat group Peach Sandstorm. The report mentioned how the group used spraying on the Entra ID accounts based in the defense and medical sector. 

And the 2019 Citrix breach, where attackers were believed to have accessed internal documents over a period of months, is generally cited as a spraying case. Months. That is the detection gap this technique creates.

Why “Just Turn On MFA” Isn’t Finished

Multi Factor Authentication or MFA is the most effective mechanism when it comes to attack control. This should be installed everywhere. 

Talos recorded how the Play Group bypassed MFA through social engineering help desks. See MFA is only as secure as its process so when MFA requires a secondary token, these attackers simply call the company’s help desk pretending to be an employee. The person at the help desk then gives out all the information without checking the accuracy of the caller’s ID. and this is how the encryption wall of MFA remained secure but the attackers still bypassed it. 

Any environment serious about this needs to treat help desk verification as part of the authentication perimeter, because attackers already do.

What Detection Has to Watch Instead

Counting failures per account misses the pattern by design.

Individual events often look harmless but when these are clubbed together to view the data, the true threat is much more obvious. For example a single password used across a vast population of many accounts seeing failure during a short span of time

That requires centralized logging across every internet-facing system tied to the directory, which is unglamorous infrastructure work and the reason so many organizations skip it.

Final Analysis

Password spraying is still used largely today because it is cheap and works against the most easy safety net: a poorly designed and easy to guess password. 

The most shocking part isn’t the relative easiness of the attack, it is that most of the organizations who have been a victim of such attacks have security teams, budgets and even policies in place. That’s why it isn’t really a security problem, it’s a seriousness problem. Midnight Blizzard got in through a test tenant nobody had thought about in years.

Which suggests the most useful question is not whether the lockout policy is tuned correctly. The most helpful insight would be to know about the number of authentication endpoints that exist which no one has paid attention to since the person responsible for building them left. 

Frequently Asked Questions

What are the key differences between password spraying and using brute force?

Ans. Brute force targets one account with many passwords. Spraying targets many accounts with a few common passwords, specifically to stay below lockout thresholds.

Does account lockout stop password spraying?

Ans. No. Lockout thresholds are published and attackers simply stay beneath them, which makes the policy a rate limit rather than a defense.

Is MFA enough on its own?

Ans. It is the strongest single control but not complete. Documented attacks have bypassed it by social-engineering help desks into enrolling attacker-controlled devices.

What is the most commonly missed exposure?

Ans. Forgotten internet-facing systems and unused tenants. Several major intrusions began at an endpoint the organization had stopped thinking about.

Sources

Semperis — what is password spraying, by Huy Kha, Senior Identity & Security Architect, for the attack mechanics, the threat actor profiles and the campaign summaries, each endnoted to Microsoft, Talos Intelligence and MITRE ATT&CK




Related Posts
How Email Authentication Fits Into a Layered Cybersecurity Strategy
How Email Authentication Fits Into a Layered Cybersecurity Strategy

One convincing email can be sufficient to pose major problems regarding security for a business. An email that appears to…

7 Best Client Intake Software Tools in 2026 for Service Businesses
7 Best Client Intake Software Tools in 2026 for Service Businesses

A client intake form works best for collecting data like names, contact information, and project needs. But what does a…

Top Salesforce Consulting Companies: How to Choose the Right One
Top Salesforce Consulting Companies: How to Choose the Right One

Salesforce consulting firm was not something that is too difficult to choose. But nowadays, there are too many options available…

How IT Teams Can Protect Data Across Thousands of Employee Devices
How IT Teams Can Protect Data Across Thousands of Employee Devices

Protecting employees’ data from when they get hired and get their first laptop to the day the laptop finally gets…

Recovering Lost Access: When to File Recovery Claims vs. Starting Over with Established Profiles
Recovering Lost Access: When to File Recovery Claims vs. Starting Over with Established Profiles

ALT: Recovering lost access to a profile IMG SRC: https://www.howtogeek.com/microsoft-excel-ways-to-recover-lost-work/  Losing access to an old online profile can be frustrating,…

privacy-preserving-identity-verification
Top 10 Privacy-Preserving Identity Verification Providers

Choosing the best identity verification software is a high-stakes decision for any business that verifies customers remotely, identity documents, facial…

data mismanagement injury cases risks
5 Data Management Problems That Can Put Personal Injury Cases at Risk

Personal injury cases deal with a lot of information, ranging from medical records and accident reports to insurance documents and…

connected world data safety enhancement practices
Building Better Data Safety Habits in a Connected World

Nowadays, there is a lot of data say it in laptops, phones, cloud platforms, messaging tools, and in AI-powered applications.…

Ransomware Risk From Vendors
The Ransomware Risk You’re Not Monitoring: Your Vendors

Ransomeware used to be random. Attackers sent out mass emails and just waited to see who clicked, but that’s not…