Skip to main content
Security Products

Cybercrime Groups Exploit Vishing and SSO Trust in Rapid SaaS Extortion Attacks

Cybercrime Groups Exploit Vishing and SSO Trust in Rapid SaaS Extortion Attacks Image: Primary
Cybersecurity researchers have identified two cybercrime groups carrying out rapid, high-impact attacks that operate almost entirely within SaaS environments while leaving minimal traces. The clusters, Cordial Spider (also tracked as BlackFile, CL-CRI-1116, O-UNC-045, and UNC6671) and Snarky Spider (also tracked as O-UNC-025 and UNC6661), have been attributed to high-speed data theft and extortion campaigns. Both hacking groups are assessed to be active since at least October 2025. Snarky Spider is a native English-speaking crew with ties to the e-crime ecosystem known as The Com. In most cases, these adversaries use voice phishing (vishing) to direct targeted users to malicious, SSO-themed adversary-in-the-middle (AiTM) pages, where they capture authentication data and pivot directly into SSO-integrated SaaS applications, CrowdStrike's Counter Adversary Operations said in a report. By operating almost exclusively within trusted SaaS environments, they minimize their footprint while accelerating time to impact. The combination of speed, precision, and SaaS-only activity creates significant detection and visibility challenges for defenders. In a report published back in January 2026, Google-owned Mandiant revealed that the two clusters represent an expansion in threat activity that employs tactics consistent with extortion-themed attacks carried out by the ShinyHunters group. This involves impersonating IT staff in calls to deceive victims and obtain their credentials and multi-factor authentication (MFA) codes by directing them to phishing pages. As recently as last week, Palo Alto Networks Unit 42 and Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) assessed with moderate confidence that the attackers behind CL-CRI-1116 are also most likely associated with The Com, adding that the intrusions primarily rely on living-off-the-land (LotL) techniques, as well as utilize residential proxies to conceal their geographic location and bypass basic IP-based reputation filters. CL-CRI-1116 activity has been actively targeting the retail and hospitality space since February 2026, specifically leveraging vishing attacks impersonating IT help desk personnel in combination with phishing login sites to steal credentials, researchers Lee Clark, Matt Brady, and Cuong Dinh said. Attacks mounted by the two groups are known to register a new device in order to bypass MFA and maintain access to compromised access -- but not before removing existing devices -- following which the threat actors move to suppress automated email notifications related to unauthorized device registration by configuring inbox rules that automatically delete such messages. The next stage entails pivoting to targeting high-privileged accounts via further social engineering by scraping internal employee directories. Upon again elevated access, the adversaries break into target SaaS environments to look for high-value files and business-critical reports in Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce, and then exfiltrate data of interest to infrastructure under its control. In most observed cases, these credentials grant access to the organization's identity provider (IdP), providing a single point of entry into multiple SaaS applications, CrowdStrike said. By abusing the trust relationship between the IdP and connected services, the adversaries bypass the need to compromise individual SaaS apps and instead move laterally across the victim's entire SaaS ecosystem with a single authenticated session.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital AI
Capital AI

Buildots raises $130 million for construction AI platform

Buildots, a startup using AI to help accelerate construction of data centers, chip factories and hospitals, raised $130 million in new financing, Bloomberg reported. The bounded report does not identify investors, the financing ty...

AI Capital
AI Capital

Tandem Health raises €86.49 million for European clinic AI platform

Stockholm-based Tandem Health has raised €86.49 million ($100 million) in a Series B led by EQT-managed Scaleup Europe Fund, bringing its total funding to €138.38 million. Tandem said its medical-assistant software supports clinic...

Capital Products
Capital Products

Ferm Labs raises €3 million for ingredient bioprocessing expansion

Ferm Labs, a Zug-based B2B ingredient startup, secured €3 million to scale its bioprocessing platform, according to EU-Startups. CDP Venture Capital led the round through its Green Transition Fund/NextGenerationEU, joined by Fund...

AI Capital
AI Capital

Aeon acquires Aware Health after Seed extension tops €12 million

Zurich preventive-health company Aeon has acquired German blood-diagnostics platform Aware Health and closed a Seed extension that brings its total Seed funding above €12 million. Aeon said it acquired Aware's technology platform,...

Products AI
Products AI

BRKZ announces $31 million to expand Saudi procurement platform

Saudi building-materials procurement platform BRKZ announced $31 million in new capital: $13 million in Series B equity and an $18 million growth-debt commitment under its previously announced venture-debt facility. BRKZ said it ...

Robotics Infrastructure
Robotics Infrastructure

MIT spinout deploys recycled-plastic composite trusses for Army Corps bridge

MIT spinout Atlas Building Composites has supplied recycled-composite trusses for a 40-foot bridge built by the U.S. Army Corps of Engineers in a Massachusetts wetland. Atlas uses waterless plastic recycling, fiberglass reinforcem...