Cordial Spider
Cordial Spider is a financially motivated threat actor affiliated with The Com and closely aligned with Scattered Spider. It is also tracked as BlackFile, CL-CRI-1116, O-UNC-045, and UNC6671. Since at least October 2025, researchers have observed Cordial Spider conducting rapid data theft and extortion campaigns that operate almost exclusively within trusted SaaS environments, including Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce, creating significant visibility challenges for defenders. The group primarily targets U.S.-based organizations across multiple sectors, including academic, aviation, retail, hospitality, automotive, financial services, legal, and technology. Separate reporting specifically noted targeting of retail and hospitality organizations since February 2026. Its operations rely heavily on voice phishing and other social engineering, including impersonation of IT help desk or support personnel via phone calls, texts, and emails, to direct victims to adversary-in-the-middle phishing pages that mimic legitimate single sign-on or identity provider portals. These pages capture credentials, MFA codes, session keys, or tokens, which are then used to access the victim’s identity provider and pivot across connected SaaS applications through existing trust relationships. After initial access, Cordial Spider establishes persistence by removing existing MFA devices and registering attacker-controlled devices, including a broader mix of mobile devices and QEMU-based emulators. The actor suppresses detection by deleting security emails and creating inbox rules to filter or remove messages related to alerts, incidents, or MFA changes. It also uses living-off-the-land techniques and residential proxy or VPN services, including Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, and NSOCKS, to obscure origin and evade IP-based detection. Cordial Spider targets privileged accounts through additional social engineering and internal directory scraping, then searches SaaS platforms for high-value files, business-critical reports, and sensitive data. Reported search themes include terms such as confidential, SSN, contracts, and VPN. The group’s objective is data theft for extortion, with reported ransom demands often in the seven-figure range. Some non-paying victims have reportedly also faced DDoS attacks. CrowdStrike described Cordial Spider and Snarky Spider as a newer generation using much of Scattered Spider’s playbook, while noting they have not demonstrated the same impact or technical capability as Scattered Spider.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting aggressive SaaS-centric data theft campaigns by abusing SSO-integrated cloud environments, using vishing and adversary-in-the-middle phishing to steal credentials and session tokens, then manipulating MFA settings for persistence and rapidly exfiltrating sensitive data.
Conducting rapid, high-impact data theft and extortion campaigns primarily within SaaS environments, using vishing and adversary-in-the-middle phishing to capture credentials and pivot into SSO-integrated applications.
Financially motivated threat group affiliated with The Com conducting rapid data theft and extortion attacks against organizations across multiple sectors, using voice-phishing and social engineering to compromise identity platforms and move through SaaS environments.
Financially motivated extortion and rapid data-theft operations targeting identity platforms and SaaS environments, especially across critical infrastructure and enterprise sectors. The group is described as closely aligned with Scattered Spider and part of the broader The Com ecosystem.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.