Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
phishing-campaign-intelligencevoice-social-engineeringcredential-access-methoddata-exfiltration-method

Cordial Spider and Snarky Spider drive SaaS extortion via vishing and AiTM phishing

Updated 19d agoFirst seen Apr 30, 20264 sources

CrowdStrike reported that two financially motivated threat groups tied to The ComCordial Spider and Snarky Spider — are carrying out rapid data-theft and extortion campaigns against U.S.-based organizations across critical infrastructure and enterprise sectors, including aviation, retail, hospitality, financial services, legal, technology, automotive, and academia. The actors are closely aligned with the Scattered Spider playbook and have used voice phishing, text messages, email, and other social-engineering tactics since at least October 2025 to compromise identity platforms, steal credentials, session keys, and tokens, and pivot through victims’ SaaS environments. Ransom demands have reportedly reached seven figures, and some victims have also faced DDoS attacks or swatting.

The intrusions rely on adversary-in-the-middle phishing pages that mimic legitimate single sign-on and identity-provider portals, enabling access to services such as SharePoint, HubSpot, and Google Workspace while largely bypassing traditional endpoint defenses. After gaining access, the attackers register their own MFA devices or emulators, disable or suppress alerts through inbox rules and email deletion, and move quickly to search for sensitive data and exfiltrate it, in some cases within an hour of initial access. Researchers said the groups differ in tradecraft — including operating hours, phishing infrastructure, leak sites, and MFA-registration methods — while both use commercial VPNs and residential proxy networks such as Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, and NSOCKS to blend into normal traffic and evade detection.

Share:
Cordial Spider and Snarky Spider drive SaaS extortion via vishing and AiTM phishing
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 8, 202619d ago

Researchers report Pink extortion group targeting Microsoft 365 data

Reporting based on Palo Alto Networks Unit 42 and Gurucul described a cybercrime group called Pink, believed linked to the broader Com network, using vishing and credential-harvesting domains to access Microsoft 365 environments. The group was said to exfiltrate data from OneDrive and SharePoint with legitimate tools and extort victims using compromised internal accounts.

New Pink cybercrime group targets corporate data using vishing and cloud theft | brief | SC Media
Apr 30, 20262mo ago

Researchers detail tradecraft used in the extortion campaigns

Researchers reported that the groups targeted primarily U.S.-based organizations across critical infrastructure and enterprise sectors, using adversary-in-the-middle phishing pages, MFA device registration, alert suppression, residential proxies, and rapid data exfiltration. Reporting also highlighted differences between the two crews' operating methods, including device preferences, phishing infrastructure, and harassment tactics such as DDoS attacks or swatting in some cases.

Two new extortion crews are speedrunning the Scattered Spider playbook | CyberScoop
Oct 1, 20259mo ago

Cordial Spider and Snarky Spider begin SaaS extortion intrusions

Since at least October 2025, CrowdStrike and other researchers tracked The Com-affiliated groups Cordial Spider and Snarky Spider conducting rapid data theft and extortion campaigns. The actors used vishing, phishing pages, and social engineering to compromise identity platforms, steal credentials or session tokens, and pivot through victims' SaaS environments.

Two new extortion crews are speedrunning the Scattered Spider playbook | CyberScoop
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
1 linked
Hubspot
Organizations
14 linked
CrowdStrikeMullvadOxylabsNetNutGenymobileHubspotMicrosoft CorporationGoogleCyberScoopPalo Alto NetworksInfaticaRetail & Hospitality Information Sharing and Analysis Center9Proxynsocks
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.