Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Since October 2025, two financially motivated threat actors, CORDIAL SPIDER and SNARKY SPIDER, have conducted targeted campaigns combining voice phishing, credential harvesting, and MFA abuse to gain persistent access to enterprise SaaS environments via compromised identity infrastructure. Both actors operate exclusively through SSO-integrated SaaS applications, bypassing endpoint detection controls entirely. The primary business risks are unauthorized data access, rapid exfiltration, and extortion against organizations that rely on federated identity for SaaS access.

Author

Tech Jacks Solutions