Cybercrime Groups Cordial Spider and Snarky Spider Target SaaS with Rapid High‑Impact Attacks
Monitor SaaS logs for rapid high‑impact attacks from Cordial Spider and Snarky Spider.
Enable logging and alerting for rapid high‑impact attacks from Cordial Spider and Snarky Spider.
Summary
Cybersecurity researchers have warned that two cybercrime groups, Cordial Spider (also known as BlackFile, CL‑CRI‑1116, O‑UNC‑045, and UNC6671) and Snarky Spider (O‑UNC‑025, UNC6661), are conducting rapid, high‑impact attacks that largely stay within SaaS environments. The groups leave minimal traces, making detection difficult, and focus on high‑speed data theft from cloud‑based applications. Their tactics include exploiting misconfigured SaaS services, leveraging stolen credentials, and using automated scripts to exfiltrate data. The warning was issued after analysts observed a spike in compromised accounts across multiple SaaS platforms. The attacks are designed to maximize data loss while minimizing detection time. Organizations should review their SaaS security posture and implement stricter access controls. The threat actors are actively targeting businesses that rely heavily on SaaS for core operations.
Key changes
- Two groups, Cordial Spider (BlackFile, CL‑CRI‑1116, O‑UNC‑045, UNC6671) and Snarky Spider (O‑UNC‑025, UNC6661), are active.
- They conduct rapid, high‑impact attacks primarily within SaaS environments.
- Attacks leave minimal traces, making detection difficult.
- Focus on high‑speed data theft from cloud‑based applications.
- Warning issued after spike in compromised SaaS accounts.