Total SMB BruteForcer is a credential-guessing hacktool used to perform password-spraying and dictionary attacks against SMB authentication. Leafminer used it within compromised networks to identify valid credentials and support lateral movement. Its password-spraying use corresponds to MITRE ATT&CK sub-technique T1110.003, testing candidate passwords across multiple accounts rather than concentrating repeated guesses on a single account. Leafminer's operational toolkit included dictionary-input files suitable for use with Total SMB BruteForcer and THC Hydra. The tool was used in Leafminer's cyberespionage operations targeting government organizations and businesses across the Middle East. It is an offensive authentication-testing utility rather than a demonstrated standalone implant or malware payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by Leafminer to conduct password spraying within victim networks.
Used for SMB password attacks and lateral movement. It accepts separate input files containing target IP addresses, usernames, and passwords.
SMB-focused brute force/password spraying tool used to attempt internal credential validation against SMB services.
Tool used to conduct SMB password spraying/brute force attempts to obtain valid credentials inside victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.