Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace
ID: ea31bd31-0967-5d3c-9151-2172eee5b77b
STIX ID: report--ea31bd31-0967-5d3c-9151-2172eee5b77b
Feed Name: cybersecurityNews.com
Threat Score
Since October 2025, researchers have tracked two adversary groups (CORDIAL SPIDER and SNARKY SPIDER) conducting high-speed data theft from trusted SaaS environments by using vishing to deliver AiTM SSO phishing, stealing session tokens, manipulating MFA, and rapidly exfiltrating sensitive documents via anonymization services; these campaigns emphasize IdP abuse and visibility gaps in SaaS security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
