Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
ID: 7d396776-3209-530b-8e85-08fdf4f748a2
STIX ID: report--7d396776-3209-530b-8e85-08fdf4f748a2
Feed Name: The Hacker News
Cybersecurity researchers warn that two cybercrime clusters—Cordial Spider (aka BlackFile/UNC6671) and Snarky Spider (aka UNC6661)—are conducting rapid, high-impact extortion and data theft operations that operate primarily inside trusted SaaS environments. Using vishing to lure victims to SSO-themed adversary-in-the-middle pages, the actors capture credentials and MFA codes, register new devices to bypass MFA, delete notification emails via inbox rules, and pivot through compromised identity providers to rapidly exfiltrate sensitive files from Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce, creating significant detection challenges for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
