logo

Defending Against CORDIAL SPIDER and SNARKY SPIDER with Falcon Shield

ID: 41eb078a-7405-551a-b736-8ca9a80679e6

STIX ID: report--41eb078a-7405-551a-b736-8ca9a80679e6

Feed Name: Crowdstrike Blog

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-05-01

Author: Falcon Shield - Counter Adversary Operations

...
...

Since October 2025, CrowdStrike observed CORDIAL SPIDER and SNARKY SPIDER executing fast, SaaS-focused attacks that rely on vishing and adversary-in-the-middle SSO pages to capture credentials and session tokens, allowing attackers to pivot across an organization’s SaaS ecosystem with minimal endpoint footprint; the report explains the tradecraft, detection challenges, and how Falcon Shield detects anomalous sign-ins and session behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.