AiTM Login Pages Fuel Attacks on SharePoint, HubSpot, and Google Workspace
ID: de9dfa99-2e2b-533b-9781-782014fadb72
STIX ID: report--de9dfa99-2e2b-533b-9781-782014fadb72
Feed Name: Cyber Press
Threat Score
This report describes active, high-speed data theft and extortion campaigns by two adversary groups (CORDIAL SPIDER and SNARKY SPIDER) that target SaaS environments (SharePoint, HubSpot, Google Workspace) using vishing and AiTM phishing to capture session tokens, manipulate MFA, and rapidly exfiltrate sensitive corporate data—often within an hour—while leveraging residential proxies and VPNs to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
