Password Spray Attack - it can be defined as one method being used by cyber criminals to gain access on some organisations or individuals using a commonly used known passwords such as "password', 1234, or 'qwerty'. So the first thing they do is harvest emails and then 'spray' using the those weak passwords, hence password spray attack.
Brute Force Attack - is the exact opposite, the hackers are guessing our password, and works on every possible combinations in the hope that they will get it correctly. This is much more difficult though and might take some time for criminals.
Usually the initial step is through spear phishing, and then if they have harvested emails, then they can do any of the attacks above. And then once they hijack your machines, they can do anything they want, like installing malware or stealing our crypto credentials directly.
How do we protect ourselves from such attacks?
Of course we should used strong passwords and don't use anything that can be guessed easily, like your birthdate, initials of your name. And when possible used a longer password at least 10 characters with combinations of symbols and numbers.
And this thread can help you out:
[GUIDE] How to Create a Strong/Secure Password.
References:
https://www.microsoft.com/security/blog/2020/04/23/protecting-organization-password-spray-attacks/https://www.moqdigital.com/insights/password-spray-attackshttps://www.kaspersky.com/resource-center/definitions/brute-force-attack