Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Financially Motivated

Cordial Spider

Also known ascordial_spider

Cordial Spider is a financially motivated threat actor affiliated with The Com and closely aligned with Scattered Spider. It is also tracked as BlackFile, CL-CRI-1116, O-UNC-045, and UNC6671. Since at least October 2025, researchers have observed Cordial Spider conducting rapid data theft and extortion campaigns that operate almost exclusively within trusted SaaS environments, including Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce, creating significant visibility challenges for defenders. The group primarily targets U.S.-based organizations across multiple sectors, including academic, aviation, retail, hospitality, automotive, financial services, legal, and technology. Separate reporting specifically noted targeting of retail and hospitality organizations since February 2026. Its operations rely heavily on voice phishing and other social engineering, including impersonation of IT help desk or support personnel via phone calls, texts, and emails, to direct victims to adversary-in-the-middle phishing pages that mimic legitimate single sign-on or identity provider portals. These pages capture credentials, MFA codes, session keys, or tokens, which are then used to access the victim’s identity provider and pivot across connected SaaS applications through existing trust relationships. After initial access, Cordial Spider establishes persistence by removing existing MFA devices and registering attacker-controlled devices, including a broader mix of mobile devices and QEMU-based emulators. The actor suppresses detection by deleting security emails and creating inbox rules to filter or remove messages related to alerts, incidents, or MFA changes. It also uses living-off-the-land techniques and residential proxy or VPN services, including Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, and NSOCKS, to obscure origin and evade IP-based detection. Cordial Spider targets privileged accounts through additional social engineering and internal directory scraping, then searches SaaS platforms for high-value files, business-critical reports, and sensitive data. Reported search themes include terms such as confidential, SSN, contracts, and VPN. The group’s objective is data theft for extortion, with reported ransom demands often in the seven-figure range. Some non-paying victims have reportedly also faced DDoS attacks. CrowdStrike described Cordial Spider and Snarky Spider as a newer generation using much of Scattered Spider’s playbook, while noting they have not demonstrated the same impact or technical capability as Scattered Spider.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics38 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1598×4
Phishing for Information
T1598.003
Spearphishing Link
T1598.004×2
Spearphishing Voice
TA0042
Resource Development
1 technique
T1586
Compromise Accounts
T1586.002
Email Accounts
TA0001
Initial Access
2 techniques
T1078×6
Valid Accounts
T1078.004
Cloud Accounts
T1566
Phishing
T1566.004×5
Spearphishing Voice
TA0003
Persistence
2 techniques
T1078×6
Valid Accounts
T1078.004
Cloud Accounts
T1556×4
Modify Authentication Process
TA0004
Privilege Escalation
1 technique
T1078×6
Valid Accounts
T1078.004
Cloud Accounts
TA0005
Stealth
2 techniques
T1070×3
Indicator Removal
T1078×6
Valid Accounts
T1078.004
Cloud Accounts
TA0112
Defense Impairment
1 technique
T1556×4
Modify Authentication Process
TA0006
Credential Access
5 techniques
T1539×2
Steal Web Session Cookie
T1556×4
Modify Authentication Process
T1557×2
Adversary-in-the-Middle
T1621
Multi-Factor Authentication Request Generation
T1649×3
Steal or Forge Authentication Certificates
TA0007
Discovery
2 techniques
T1087×3
Account Discovery
T1526
Cloud Service Discovery
TA0009
Collection
3 techniques
T1114
Email Collection
T1114.003×2
Email Forwarding Rule
T1213×4
Data from Information Repositories
T1557×2
Adversary-in-the-Middle
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.002
External Proxy
T1090.003×2
Multi-hop Proxy
TA0010
Exfiltration
3 techniques
T1041
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
T1567×2
Exfiltration Over Web Service
TA0040
Impact
2 techniques
T1498×2
Network Denial of Service
T1657
Financial Theft
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
May 2, 2026
Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

Conducting aggressive SaaS-centric data theft campaigns by abusing SSO-integrated cloud environments, using vishing and adversary-in-the-middle phishing to steal credentials and session tokens, then manipulating MFA settings for persistence and rapidly exfiltrating sensitive data.

Read more
the hacker newsNews
May 1, 2026
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

Conducting rapid, high-impact data theft and extortion campaigns primarily within SaaS environments, using vishing and adversary-in-the-middle phishing to capture credentials and pivot into SSO-integrated applications.

Read more
scworldNews
May 1, 2026
2 threat groups linked to The Com target critical infrastructure with data theft | brief | SC Media

Financially motivated threat group affiliated with The Com conducting rapid data theft and extortion attacks against organizations across multiple sectors, using voice-phishing and social engineering to compromise identity platforms and move through SaaS environments.

Read more
cyberscoopNews
Apr 30, 2026
Two new extortion crews are speedrunning the Scattered Spider playbook | CyberScoop

Financially motivated extortion and rapid data-theft operations targeting identity platforms and SaaS environments, especially across critical infrastructure and enterprise sectors. The group is described as closely aligned with Scattered Spider and part of the broader The Com ecosystem.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping27

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.