SMBAutoBrute - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:11:22 UTC Home > List all groups > List all tools > List all groups using tool Invoke-SMBAutoBrute Tool: Invoke-SMBAutoBrute Names Invoke-SMBAutoBrute Category Tools Type Credential stealer Description One of my favorite post-ex metasploit modules is smb_login. It's great for running a quick test using credentials you've discovered. One of the problems with it is that there is nothing that prevents you from locking out accounts. Plus, you have to create user list which means dumping users | cut | sed | awk, blah blah blah. Information Last change to this tool card: 24 June 2020 Download this tool card in JSON format All groups using tool Invoke-SMBAutoBrute Changed Name Country Observed APT groups   Wizard Spider, Gold Blackburn 2014-May 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=664b8eb2-3747-4b8d-ae37-7ab489d554a6 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=664b8eb2-3747-4b8d-ae37-7ab489d554a6 Page 1 of 1