Snarky Spider
Snarky Spider is a financially motivated threat group affiliated with The Com and closely aligned with Scattered Spider. It is also tracked as O-UNC-025 and UNC6661. CrowdStrike reported the group has been active since at least October 2025 and primarily targets U.S.-based organizations across sectors including academic, aviation, retail, hospitality, automotive, financial services, legal, and technology, as well as multiple critical infrastructure sectors. The group conducts rapid data theft and extortion campaigns, often operating almost exclusively within trusted SaaS environments such as Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce to minimize endpoint visibility and accelerate impact. Its intrusion chain relies heavily on voice phishing and social engineering, including impersonation of IT support or help desk personnel via phone calls, as well as text messages and emails, to direct victims to adversary-in-the-middle phishing pages that mimic legitimate single sign-on or identity provider portals. These pages capture credentials, MFA codes, session keys, or tokens, allowing access to the victim identity provider and lateral movement across SSO-integrated SaaS applications. After compromise, Snarky Spider establishes persistence by removing existing MFA devices, registering attacker-controlled devices, and deleting or filtering security notifications through inbox rules. The content specifically states that Snarky Spider almost exclusively enrolls Genymobile Android emulators for connected-device management. The group also scrapes internal employee directories to identify privileged users, targets high-privileged accounts through additional social engineering, searches SaaS platforms for high-value information, and can begin high-volume data exfiltration in under an hour. The group uses living-off-the-land techniques and residential proxy or VPN services to conceal origin and evade IP-based detection; providers named in the content include Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, and NSOCKS. Its operations are focused on data theft for extortion, with reported ransom demands often reaching seven figures. The content also states that some victims have faced follow-on harassment including swatting, and some non-paying victims have experienced DDoS attacks. CrowdStrike described Snarky Spider as a native English-speaking crew and as part of a new generation using much of Scattered Spider’s playbook.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting aggressive SaaS-focused intrusions and data theft, with especially rapid exfiltration timelines, using vishing and AiTM phishing for initial access, MFA device enrollment for persistence, and cloud-native searches to identify and steal sensitive data.
Conducting rapid SaaS-centric data theft and extortion operations, beginning exfiltration very quickly after compromise and relying on vishing and AiTM phishing to obtain credentials and access SSO-connected services.
Financially motivated threat group affiliated with The Com conducting rapid data theft and extortion attacks against organizations across multiple sectors, using voice-phishing and social engineering to compromise identity platforms and move through SaaS environments.
Financially motivated extortion and data-theft activity targeting identity systems and SaaS ecosystems. The group is described as closely aligned with Scattered Spider and uses aggressive harassment tactics in follow-on extortion activity.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.