Cyber Security News

Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft

Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure automation, role-based operations, and real-time credential harvesting into a single criminal SaaS console.

It exemplifies how phishing has evolved from static kits into resilient cybercrime-as-a-service ecosystems optimized for scale, specialization, and rapid exit in the face of law-enforcement pressure.

Instead of distributing a simple HTML kit, the author offers a service that bundles domain registration, DNS, CDN, brand cloning, and session monitoring with strict access controls and hierarchical roles, mirroring legitimate SaaS operations on the criminal side.

Work Panel operates as a cybercrime-as-a-service (CaaS) platform, allowing multiple threat actors to run parallel campaigns with their own API keys and hosting integrations while sharing the same orchestration layer.

With one-click actions, operators can register phishing domains, clone legitimate login portals, and deploy isolated phishing sites in minutes, dramatically compressing the time from campaign planning to live account takeover.

The platform automates infrastructure provisioning through integrations with NiceNIC for domain registration, Cloudflare for DNS zones, and Bunny CDN for traffic redirection and email click hosts, alongside a dedicated Caddy reverse proxy for phishing pages.

Each phishing site runs as its own isolated instance with dedicated processes and configurations, so takedown of one domain does not cascade across the broader operation, a design pattern seen in other MFA-bypassing PhaaS platforms such as Tycoon 2FA and W3LL.

A built-in “kill switch” allows administrators to instantly dismantle active infrastructure domains, processes, and DNS records providing a rapid exit strategy if law enforcement, incident response teams, or upstream providers begin disrupting the campaign.

Okta’s threat intelligence team recently detailed “Work Panel,” a polished web application that functions as an operator console for voice phishing crews targeting identity providers such as Okta, Microsoft 365, and Salesforce.

The caller workspace (Source: okta).

API keys for external services can be rotated without redeploying the environment, preserving operational security and persistence even under active investigation or infrastructure blocking.

Work Panel Vishing Platform

Unlike traditional kits, Work Panel enforces a clear hierarchy with three distinct roles: admin, manager, and caller, backed by server-side access controls that compartmentalize sensitive data.

Callers often low-level recruits from underground forums are restricted to live victim interactions and cannot see stolen credentials, reducing insider risk and centralizing control with campaign managers and admins.

Callers conduct vishing calls using pretexting scripts and integrated tools like a Company Lookup feature that pulls employee names, titles, and phone numbers from commercial data sources such as RocketReach, enabling highly tailored social engineering against staff in colleges, universities, and enterprises.

The manager workspace (Source: okta).

Managers oversee live phishing sessions via a real-time dashboard that shows victim activity; using a “push” mechanism, they walk targets through staged authentication flows and MFA prompts while callers keep them engaged on the phone.

Captured usernames, passwords, and MFA codes stream into a session panel visible only to managers, who can exfiltrate the haul via connected Telegram bots in near real time.

Admins own the end-to-end operation: they configure infrastructure integrations, manage API keys, define voice and email phishing templates, monitor caller activity, and audit all actions through detailed logs.

Work Panel also supports automated email phishing campaigns with dynamic branding based on cloned tenant environments, aligning with broader PhaaS trends seen in platforms like Tycoon 2FA, Whisper 2FA, and Kali365 that specialize in MFA interception and session hijacking.

By treating social engineering as interchangeable labor and insulating high-value assets stolen credentials and session tokens at elevated roles, Work Panel shows how organized cybercrime now mirrors mature enterprise architectures with separation of duties and controlled access to secrets.

For defenders, Work Panel is another proof point that MFA alone is insufficient against adversary-in-the-middle and vishing-led workflows; phishing-resistant MFA (FIDO2, passkeys), strict help desk procedures, behavioral monitoring for unusual session cookie reuse.

$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

5 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

5 hours ago

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…

6 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

6 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

7 hours ago

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…

7 hours ago