BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

SaaS Hackers Launch “Silent” Extortion Campaigns

SaaS-based vishing attacks bypass MFA for high-speed data theft and extortion

  • Two cybercrime groups, Cordial Spider and Snarky Spider, are conducting rapid, high-impact data theft and extortion campaigns primarily within trusted SaaS environments.
  • The attackers use voice phishing (vishing) to trick users into visiting malicious SSO-themed pages, stealing authentication data to pivot directly into cloud applications.
  • These intrusions, active since at least October 2025, present significant detection challenges as they leave minimal footprints and leverage living-off-the-land techniques.
  • Once inside, the groups target high-privileged accounts and exfiltrate valuable data from platforms like Google Workspace and Salesforce to infrastructure under their control.
  • Mandiant research links the clusters’ tactics to extortion-themed attacks previously associated with the ShinyHunters group.

Cybersecurity firms CrowdStrike and Mandiant warned in May 2026 of two sophisticated cybercrime groups, Cordial Spider and Snarky Spider, executing swift and stealthy attacks within corporate software environments. These adversaries, active since at least October 2025, specialize in high-speed data theft and extortion by impersonating IT help desk personnel. According to a CrowdStrike report, they use voice phishing to direct targets to adversary-in-the-middle pages that capture login credentials.

- Advertisement -

Consequently, they bypass multi-factor authentication by registering new devices and deleting automated security alerts from victim inboxes. “By operating almost exclusively within trusted SaaS environments, they minimize their footprint while accelerating time to impact,” the researchers noted. This method provides a single point of entry into an organization’s entire suite of cloud applications through the identity provider.

Meanwhile, a January 2026 report from Google-owned Mandiant revealed these clusters represent an expansion of threat activity consistent with the ShinyHunters group. As recently as last week, Palo Alto Networks Unit 42 and the RH-ISAC assessed with moderate confidence that the actors behind CL-CRI-1116 are likely associated with the e-crime ecosystem known as The Com. The groups primarily rely on living-off-the-land techniques and use residential proxies to hide their locations.

After initial access, the threat actors pivot by scraping internal directories to find and compromise high-privileged accounts. They then hunt for business-critical files in platforms like Microsoft SharePoint and HubSpot before exfiltrating the data. This combination of speed, precision, and SaaS-only activity creates significant visibility challenges for security teams trying to defend their organizations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Drake’s New Song Demands Pardon for SBF

Drake called for the release of imprisoned FTX founder Sam Bankman-Fried in a lyric...

NIO’s Onvo L80 SUV Launches, Deliveries Start Saturday

Nio's mass-market subsidiary, Onvo, officially launched the L80 family SUV on Friday, with deliveries...

Liberland Honors Ethereum Founder Buterin With Star-Shaped Medal

Vitalik Buterin received the "First Class Order of Merit of the Star of Liberland"...

Firm seeks $344M in frozen Tether tied to Iran

Gerstein Harrow LLP is seeking a court order to compel Tether to release over...

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading