CORDIALSPIDER, also tracked as O-UNC-045, is a cybercriminal intrusion cluster associated with organized vishing-driven enterprise account takeover operations. The cluster has been linked to use of Work Panel, a multi-operator criminal platform that centralizes employee research, caller management, phishing-site creation, live session monitoring, and handling of stolen authentication material. Its operations are aimed at enterprise identity and access workflows and have targeted customers of major identity and business application providers including Okta, Microsoft 365, and Salesforce. The actor’s tradecraft emphasizes social engineering over purely technical exploitation. Operations involve impersonation of internal helpdesk or support personnel, use of researched employee and organizational details to personalize pretexts, and real-time guidance of victims through authentication prompts during live calls. The associated platform supports cloning recognizable enterprise login brands, launching isolated phishing environments, sending branded phishing emails, and monitoring victim progress in real time so operators can prompt for passwords, authenticator codes, push approvals, number matching, and related authentication steps. A notable operational characteristic is separation of duties among caller, manager, and administrator roles. Low-level callers interact with targets and can access target research and calling resources, while captured credentials and session-related data are exposed to supervisory roles rather than callers. This structure reduces insider risk for the criminal operation, protects stolen access, and allows rapid replacement of front-line operators. Administrative functions include infrastructure management, secret rotation, activity logging, live operator monitoring, and rapid teardown of phishing infrastructure through a self-destruct capability. CORDIALSPIDER’s observed behavior supports capabilities including reconnaissance, initial access through phishing and vishing, credential theft, session-focused account takeover activity, defense evasion through disposable and rapidly rebuilt infrastructure, and post-exploitation abuse of compromised enterprise identities. The cluster is best characterized as financially motivated cybercrime rather than a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating or using the Work Panel platform to conduct vishing-driven enterprise account takeover campaigns against customers of identity providers, combining target research, caller management, phishing-site creation, and stolen-credential handling.
Cybercriminal intrusion cluster using the Work Panel cybercrime-as-a-service platform to conduct organized vishing campaigns targeting identity-provider customers, including credential capture and session theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.