Friday, September 11, 2026

Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft

Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure automation, role-based operations, and real-time credential harvesting into a single criminal SaaS console.

It exemplifies how phishing has evolved from static kits into resilient cybercrime-as-a-service ecosystems optimized for scale, specialization, and rapid exit in the face of law-enforcement pressure.

Instead of distributing a simple HTML kit, the author offers a service that bundles domain registration, DNS, CDN, brand cloning, and session monitoring with strict access controls and hierarchical roles, mirroring legitimate SaaS operations on the criminal side.

Work Panel operates as a cybercrime-as-a-service (CaaS) platform, allowing multiple threat actors to run parallel campaigns with their own API keys and hosting integrations while sharing the same orchestration layer.

With one-click actions, operators can register phishing domains, clone legitimate login portals, and deploy isolated phishing sites in minutes, dramatically compressing the time from campaign planning to live account takeover.

The platform automates infrastructure provisioning through integrations with NiceNIC for domain registration, Cloudflare for DNS zones, and Bunny CDN for traffic redirection and email click hosts, alongside a dedicated Caddy reverse proxy for phishing pages.

Each phishing site runs as its own isolated instance with dedicated processes and configurations, so takedown of one domain does not cascade across the broader operation, a design pattern seen in other MFA-bypassing PhaaS platforms such as Tycoon 2FA and W3LL.

A built-in “kill switch” allows administrators to instantly dismantle active infrastructure domains, processes, and DNS records providing a rapid exit strategy if law enforcement, incident response teams, or upstream providers begin disrupting the campaign.

Okta’s threat intelligence team recently detailed “Work Panel,” a polished web application that functions as an operator console for voice phishing crews targeting identity providers such as Okta, Microsoft 365, and Salesforce.

The caller workspace (Source: okta).

API keys for external services can be rotated without redeploying the environment, preserving operational security and persistence even under active investigation or infrastructure blocking.

Work Panel Vishing Platform

Unlike traditional kits, Work Panel enforces a clear hierarchy with three distinct roles: admin, manager, and caller, backed by server-side access controls that compartmentalize sensitive data.

Callers often low-level recruits from underground forums are restricted to live victim interactions and cannot see stolen credentials, reducing insider risk and centralizing control with campaign managers and admins.

Callers conduct vishing calls using pretexting scripts and integrated tools like a Company Lookup feature that pulls employee names, titles, and phone numbers from commercial data sources such as RocketReach, enabling highly tailored social engineering against staff in colleges, universities, and enterprises.

The manager workspace (Source: okta).
The manager workspace (Source: okta).

Managers oversee live phishing sessions via a real-time dashboard that shows victim activity; using a “push” mechanism, they walk targets through staged authentication flows and MFA prompts while callers keep them engaged on the phone.

Captured usernames, passwords, and MFA codes stream into a session panel visible only to managers, who can exfiltrate the haul via connected Telegram bots in near real time.

Admins own the end-to-end operation: they configure infrastructure integrations, manage API keys, define voice and email phishing templates, monitor caller activity, and audit all actions through detailed logs.

Work Panel also supports automated email phishing campaigns with dynamic branding based on cloned tenant environments, aligning with broader PhaaS trends seen in platforms like Tycoon 2FA, Whisper 2FA, and Kali365 that specialize in MFA interception and session hijacking.

By treating social engineering as interchangeable labor and insulating high-value assets stolen credentials and session tokens at elevated roles, Work Panel shows how organized cybercrime now mirrors mature enterprise architectures with separation of duties and controlled access to secrets.

For defenders, Work Panel is another proof point that MFA alone is insufficient against adversary-in-the-middle and vishing-led workflows; phishing-resistant MFA (FIDO2, passkeys), strict help desk procedures, behavioral monitoring for unusual session cookie reuse.

$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News