Okta Threat Intelligence reported that Work Panel is a multi-tenant cybercrime-as-a-service platform used to run organized vishing campaigns targeting identity and SaaS brands including Okta, Microsoft 365, and Salesforce. The platform supports the full attack chain: domain registration, brand-cloned phishing pages, target discovery through RocketReach, phishing email delivery, SIP-based call routing, and real-time credential capture with Telegram alerts. Okta linked the platform to at least one tracked intrusion cluster, O-UNC-045 / CORDIAL SPIDER, and said its behavior aligns with MITRE ATT&CK techniques covering phishing, account abuse, adversary-in-the-middle activity, and infrastructure acquisition.
Researchers described Work Panel as a mature, SaaS-like criminal operations system with role-based access for callers, managers, and administrators, plus audit logging, secret rotation, and infrastructure automation. The service also separates infrastructure operators from hired callers, reflecting a broader labor-specialized vishing ecosystem in which recruitment occurs openly on underground channels. Okta said the platform includes operational security features such as server-side segregation of stolen credentials and a self-destruct function that can remove phishing sites, processes, and DNS records, allowing campaigns to be launched, rebranded, and dismantled quickly.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
On July 28, 2026, Okta Threat Intelligence published an analysis describing Work Panel as a multi-tenant cybercrime-as-a-service platform used for organized vishing campaigns. The report linked the platform to at least one intrusion cluster tracked as O-UNC-045, also known as CORDIAL SPIDER, and detailed capabilities including phishing site cloning, target discovery, call routing, credential capture, and operational security features.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
meetcyber.net
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourceokta.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.