logo

AiTM Login Pages Fuel Attacks on SharePoint, HubSpot, and Google Workspace

ID: de9dfa99-2e2b-533b-9781-782014fadb72

STIX ID: report--de9dfa99-2e2b-533b-9781-782014fadb72

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Divya

...
...

This report describes active, high-speed data theft and extortion campaigns by two adversary groups (CORDIAL SPIDER and SNARKY SPIDER) that target SaaS environments (SharePoint, HubSpot, Google Workspace) using vishing and AiTM phishing to capture session tokens, manipulate MFA, and rapidly exfiltrate sensitive corporate data—often within an hour—while leveraging residential proxies and VPNs to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.