{"id":12568,"date":"2026-05-02T10:03:42","date_gmt":"2026-05-02T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/02\/attackers-deploy-aitm-phishing-pages-to-access-sharepoint-hubspot-and-google-workspace\/"},"modified":"2026-05-02T10:03:42","modified_gmt":"2026-05-02T10:03:42","slug":"attackers-deploy-aitm-phishing-pages-to-access-sharepoint-hubspot-and-google-workspace","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/02\/attackers-deploy-aitm-phishing-pages-to-access-sharepoint-hubspot-and-google-workspace\/","title":{"rendered":"Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace"},"content":{"rendered":"<p>    Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. <\/p>\n<p>Since October 2025, security researchers have tracked two distinct adversaries, identified as CORDIAL SPIDER and SNARKY SPIDER, conducting aggressive data theft campaigns. <\/p>\n<p>These groups operate almost exclusively within trusted SaaS environments such as SharePoint, HubSpot, and <a href=\"https:\/\/cybersecuritynews.com\/google-sheets-client-side-encryption\/\" type=\"post\" id=\"126620\" target=\"_blank\" rel=\"noreferrer noopener\">Google Workspace <\/a>to accelerate their time to impact. <\/p>\n<p>By leveraging single sign-on (SSO) integrations, they minimize their footprint and create significant visibility challenges for enterprise defenders.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-initial-access-via-vishing\"><strong>Initial Access via Vishing<\/strong><\/h2>\n<p>The adversaries initiate their attacks using targeted voice phishing (vishing) campaigns. They impersonate corporate IT support teams to create a false sense of urgency around security updates or account issues. <\/p>\n<p>This social engineering tactic directs employees to fraudulent <a href=\"https:\/\/cybersecuritynews.com\/adversary-in-the-middle-aitm-attack\/\" type=\"post\" id=\"122534\" target=\"_blank\" rel=\"noreferrer noopener\">adversary-in-the-middle<\/a> (AiTM) phishing pages that closely mimic legitimate corporate login portals, using deceptive domains like company-sso[.]com.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"877\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-1024x877.png?resize=1024%2C877&#038;ssl=1\" alt=\"\u00a0This Falcon Shield detection details a suspicious sign-in pattern consistent with AiTM phishing attacks (Source: Crowdstrike)\" class=\"wp-image-148958\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-1024x877.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-300x257.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-768x658.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-491x420.png 491w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-150x128.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-696x596.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8-1068x914.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-8.png 1308w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">\u00a0This Falcon Shield detection details a suspicious sign-in pattern consistent with AiTM phishing attacks (Source: Crowdstrike)<\/figcaption><\/figure>\n<p>When victims enter their credentials, the attackers capture authentication data and active session tokens in real time. <\/p>\n<p>Because the proxy relays this authentication directly to the legitimate service, users experience a normal login and remain entirely unaware of the compromise. <\/p>\n<p>These stolen credentials grant access to the organization\u2019s identity provider (IdP), providing a single point of entry into multiple SaaS applications. <\/p>\n<p>By abusing the trust relationship between the IdP and connected services, the attackers move laterally across the victim\u2019s entire cloud ecosystem.<\/p>\n<p>Once the attackers secure initial access, they immediately establish persistence by manipulating<a href=\"https:\/\/cybersecuritynews.com\/multifactor-authentication-is-mandatory-for-azure\/\" type=\"post\" id=\"74872\" target=\"_blank\" rel=\"noreferrer noopener\"> multifactor authentication (MFA) <\/a>settings. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"828\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-1024x828.png?resize=1024%2C828&#038;ssl=1\" alt=\"This Falcon Shield detection identifies manual deletion of security-related emails by users (Source: Crowdstrike)\" class=\"wp-image-148957\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-1024x828.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-300x243.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-768x621.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-519x420.png 519w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-150x121.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-696x563.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7-1068x864.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-7.png 1278w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">This Falcon Shield detection identifies manual deletion of security-related emails by users (Source: Crowdstrike)<\/figcaption><\/figure>\n<p>They typically remove existing MFA devices and register their own hardware to the compromised accounts while appearing to authenticate from a newly trusted device.<\/p>\n<ul class=\"wp-block-list\">\n<li>SNARKY SPIDER almost exclusively enrolls Genymobile Android emulators to manage connected devices across different operating systems.<\/li>\n<li>CORDIAL SPIDER uses a broader range of mobile devices and Windows Quick Emulators (QEMU) for its authentication needs.<\/li>\n<li>Threat actors often register their malicious devices to long-standing accounts where MFA had not previously been enabled.<\/li>\n<li>Both groups systematically delete automated security emails from the victim\u2019s inbox to hide unauthorized device registrations.<\/li>\n<li>Attackers deploy automated inbox rules to instantly filter messages containing keywords such as alert, incident, or MFA.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"h-rapid-data-exfiltration\"><strong>Rapid Data Exfiltration<\/strong><\/h2>\n<p>With secure and stealthy access established, the threat actors execute targeted searches across connected SaaS platforms to locate high-value information. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"358\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-1024x358.png?resize=1024%2C358&#038;ssl=1\" alt=\"SNARKY SPIDER begins exfiltration in under an hour (Source: Crowdstrike)\" class=\"wp-image-148956\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-1024x358.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-300x105.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-768x269.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-1200x420.png 1200w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-150x53.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-696x244.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6-1068x374.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-6.png 1400w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">SNARKY SPIDER begins exfiltration in under an hour (Source: Crowdstrike)<\/figcaption><\/figure>\n<p>They frequently query terms such as confidential, SSN, contracts, and VPN to prioritize business-critical documents and infrastructure credentials.<\/p>\n<p>Following this reconnaissance phase, the adversaries move quickly to aggregate and download massive datasets. <\/p>\n<p>In many documented incidents, SNARKY SPIDER begins high-volume<a href=\"https:\/\/cybersecuritynews.com\/data-exfiltration-prevention\/\" type=\"post\" id=\"106500\" target=\"_blank\" rel=\"noreferrer noopener\"> data exfiltration <\/a>within an hour of the initial compromise. <\/p>\n<p>These rapid breaches exploit customer misconfigurations, such as missing phishing-resistant MFA, rather than underlying vulnerabilities in the SaaS platforms themselves.<\/p>\n<p>To obscure their geographic locations and evade IP-based detection, both threat groups route their traffic through commercial VPNs and residential proxy networks. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"795\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-1024x795.png?resize=1024%2C795&#038;ssl=1\" alt=\"\u00a0Falcon Shield detection identifies when a user downloads files at a volume\u00a0 (Source: crowdstrike)\" class=\"wp-image-148955\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-1024x795.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-300x233.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-768x597.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-541x420.png 541w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-150x117.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-696x541.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5-1068x830.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-5.png 1308w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">\u00a0Falcon Shield detection identifies when a user downloads files at a volume\u00a0 (Source: crowdstrike)<\/figcaption><\/figure>\n<p>Providers like Mullvad, Oxylabs, and NetNut assign real home-user IP addresses to attackers, making malicious activity appear as benign residential traffic.<\/p>\n<p>Defending against these sophisticated techniques requires comprehensive SaaS security posture management and advanced anomaly detection. <\/p>\n<p>Platforms like<a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/defending-against-cordial-spider-and-snarky-spider-with-falcon-shield\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> CrowdStrike Falcon Shield address these visibility gaps<\/a> by applying deep SaaS expertise to analyze authentication flows and user behaviors. <\/p>\n<p>By combining entity-aware statistical models with new-age network intelligence, security teams can reliably identify anonymization services, cluster adversarial infrastructure, and disrupt these high-speed cloud threats.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/attackers-deploy-aitm-phishing-page\/\">Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/attackers-deploy-aitm-phishing-page\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October 2025, security researchers have tracked two distinct adversaries, identified as CORDIAL SPIDER and SNARKY SPIDER, conducting aggressive data theft campaigns. These groups operate [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,163,124,1601],"tags":[130],"class_list":["post-12568","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-google","category-phishing","category-sharepoint","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12568"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12568"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12568\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12568"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12568"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12568"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}