Work Panel Platform Streamlines Vishing for Enterprise Account Takeovers
A sophisticated cybercrime platform named Work Panel is enabling threat actors to conduct scalable vishing attacks, turning simple helpdesk impersonations into enterprise account takeovers.
A new cybercrime platform dubbed "Work Panel" is revolutionizing voice phishing (vishing) attacks by consolidating essential tools for enterprise account takeovers into a single, web-based operation. This platform moves beyond traditional vishing by integrating target research, caller management, phishing site creation, and the handling of stolen credentials, creating a streamlined and efficient attack pipeline.
Researchers, including those at Okta, have identified Work Panel as a comprehensive operator console linked to an intrusion cluster they track as O-UNC-045, also known as CORDIALSPIDER. Unlike simpler phishing kits, Work Panel is described as a full application designed to run a vishing-driven account takeover business, enabling threat actors to conduct campaigns at scale and rebuild operations quickly after disruptions.
The platform's design emphasizes role-based operations, separating the functions of callers, managers, and administrators. Callers are responsible for finding employees, initiating calls, and guiding targets through phishing prompts. Managers oversee live victim sessions, collecting stolen credentials or authentication codes, while administrators manage the overall infrastructure, user staffing, and operational settings. This division of labor protects valuable data and makes it easier to recruit and replace personnel.
Before initiating a call, Work Panel leverages commercial business data to gather detailed employee information, including names, corporate email addresses, phone numbers, job titles, and LinkedIn profiles. This intelligence allows callers to personalize their impersonation of helpdesk staff, making the unsolicited support calls appear more credible and increasing the likelihood of victim compliance.
Work Panel automates many technical aspects of phishing campaigns. Administrators can quickly register domains, configure DNS, and generate branded phishing sites that mimic legitimate identity providers such as Okta, Microsoft 365, and Salesforce. The platform can then deploy these sites, complete with cloned visual branding, to direct employees to fake login pages.
Each phishing panel operates independently with its own subdomain, configuration, and web server. The platform also includes advanced features like secret rotation, activity logging, live monitoring of callers, and a self-destruct function to rapidly remove phishing sites and associated DNS records, making it significantly harder for defenders to disrupt ongoing attacks through domain takedowns.
Okta recommends that organizations treat unsolicited support calls as a verification challenge. Employees should be trained on clear, trusted methods to confirm the identity of helpdesk personnel before sharing information or approving login requests. The use of phishing-resistant authenticators, such as passkeys, and the implementation of strong access controls, including location-based restrictions and prompt investigation of unusual authentication activity, are crucial defenses against these sophisticated vishing attacks.