Defending Against CORDIAL SPIDER and SNARKY SPIDER with Falcon Shield
ID: 41eb078a-7405-551a-b736-8ca9a80679e6
STIX ID: report--41eb078a-7405-551a-b736-8ca9a80679e6
Feed Name: Crowdstrike Blog
Date Published: 2026-04-30
Date Updated: 2026-05-01
Author: Falcon Shield - Counter Adversary Operations
Since October 2025, CrowdStrike observed CORDIAL SPIDER and SNARKY SPIDER executing fast, SaaS-focused attacks that rely on vishing and adversary-in-the-middle SSO pages to capture credentials and session tokens, allowing attackers to pivot across an organization’s SaaS ecosystem with minimal endpoint footprint; the report explains the tradecraft, detection challenges, and how Falcon Shield detects anomalous sign-ins and session behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
