CORDIAL SPIDER is a financially motivated, The Com-affiliated cybercrime cluster active since at least October 2025 that conducts rapid data-theft and extortion operations, primarily against U.S. organizations. It is also tracked as BlackFile, CL-CRI-1116, O-UNC-045, and UNC6671. The group is closely aligned with the Scattered Spider ecosystem and has been associated with ShinyHunters-style extortion activity. CORDIAL SPIDER primarily gains access through voice phishing and related social engineering, impersonating internal IT or help-desk personnel and directing employees to single-sign-on-themed adversary-in-the-middle authentication pages. These operations capture credentials, MFA approvals, and authenticated session tokens. The group has used the Work Panel operator platform to organize victim research, calling operations, phishing infrastructure, real-time credential collection, and management of compromised sessions. Following identity compromise, CORDIAL SPIDER abuses SSO trust relationships to access cloud applications and conducts discovery and bulk collection in SaaS environments, including enterprise collaboration, email, file-storage, CRM, and identity services. It uses residential proxies to obscure its origin and blend with expected user access patterns. The group establishes persistence through unauthorized MFA-device enrollment and may remove legitimate authenticators; it also suppresses detection by deleting security notifications and creating inbox rules. It identifies privileged users through internal directory enumeration, targets high-value business data, and rapidly exfiltrates stolen information before issuing extortion demands. Reported operations have included leak-site activity, seven-figure demands, and DDoS pressure against some non-paying victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts cloud-data theft and extortion operations targeting Microsoft 365 and other SaaS services. The cluster uses IT help-desk vishing and adversary-in-the-middle authentication pages to steal credentials, MFA approvals, and session tokens, then replays stolen sessions through residential proxies to discover, collect, and exfiltrate data.
Uses voice phishing as an identity-based initial access technique to compromise SSO accounts and exfiltrate data from SaaS applications.
Uses vishing to gain initial access by compromising single sign-on accounts and then accessing cloud productivity environments.
Uses vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.