Cordial Spider is a financially motivated cybercrime threat actor affiliated with The Com and closely aligned with Scattered Spider. It is also tracked under aliases including BlackFile, CL-CRI-1116, O-UNC-045, and UNC6671. Since at least October 2025, the group has conducted rapid data-theft and extortion operations that focus on identity compromise and movement across SaaS ecosystems rather than traditional malware-heavy intrusion chains. Cordial Spider relies heavily on voice phishing and related social-engineering lures, including phone calls, text messages, and emails impersonating IT support or help desk personnel. Victims are directed to adversary-in-the-middle single sign-on phishing pages designed to capture credentials, MFA codes, session tokens, or similar authentication artifacts. After compromising an identity provider account, the group abuses trust relationships between the identity platform and connected SaaS applications to access services such as Microsoft 365, Google Workspace, SharePoint, HubSpot, and Salesforce. Post-compromise activity emphasizes speed, stealth, and persistence inside trusted cloud services. Cordial Spider has been observed registering attacker-controlled MFA devices, removing existing MFA devices, and suppressing security notifications by deleting emails or creating inbox rules. The group also targets privileged accounts through internal directory scraping and additional social engineering, then searches SaaS platforms for high-value business data and exfiltrates it for extortion. Reporting links the actor to seven-figure extortion demands and, in some cases, follow-on pressure tactics associated with broader cluster activity such as DDoS against non-paying victims. Operationally, Cordial Spider is notable for living-off-the-land tradecraft within SaaS environments, limited endpoint footprint, and use of residential proxy services and VPN infrastructure to blend with normal traffic and evade IP-based detection. The actor has been reported targeting primarily U.S.-based organizations, including retail, hospitality, academic, aviation, automotive, financial services, legal, and technology entities. Its campaigns are characterized by rapid progression from initial access to MFA manipulation and data theft, making identity telemetry and SaaS monitoring central to detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses vishing to gain initial access by compromising single sign-on accounts and then accessing cloud productivity environments.
Uses vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts.
Uses vishing to gain access to victims' SSO-integrated SaaS applications, steal credentials and MFA codes, and register attacker-controlled MFA devices for persistence.
Uses vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.