Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities
Cybercriminals are using a platform called Work Panel to convert fake technical support calls into organized campaigns that target corporate accounts across multiple identity providers.
The service integrates target reconnaissance, phishing page cloning, telephony infrastructure, and real-time credential capture into one control panel. It is attributed to the threat group tracked as O-UNC-045, also known as Cordial Spider.
Before placing calls, operators gather names, job titles, corporate email addresses, phone numbers, and professional profiles. This information allows the caller to impersonate help-desk personnel convincingly and tailor the approach to the victim’s role.
During the call, one operator maintains contact with the employee while a manager oversees the live phishing session. The fake page can request passwords, multi-factor authentication codes, push-notification approvals, or numeric confirmations.
Credentials are not delivered to the person making the call. Instead, they are forwarded exclusively to operation managers, who can copy them or receive them via Telegram, limiting opportunities for internal theft among the criminals.
Work Panel also automates domain registration, DNS configuration, and the creation of phishing pages that mimic Okta, Microsoft 365, and Salesforce login portals. New campaigns can be prepared within minutes.
The operation separates roles among callers, managers, and administrators. Each campaign runs in isolation, allowing rapid replacement of operators, rotation of infrastructure keys, and quick rebuilding after takedowns.
Related articles
Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers
Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.
Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes
Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.
Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions
Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.
Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance
Beeline customers have encountered widespread attempts to hijack mobile numbers through unauthorized remote issuance of eSIM cards. Attackers required only a single careless confirmation from the user to complete the takeover, bypassing traditional SMS or push notifications. The scheme presented a system-level prompt on the smartphone screen requesting login to the operator's personal account, after which a virtual SIM was issued and the physical card blocked. One victim was Kommersant FM editor-in-chief Vladislav Viktorov. Specialist Alexander Baulin suggested possible infrastructure compromise at the operator, though Beeline denied this and described the incident as a coordinated attack on remote SIM issuance mechanisms. The company stated it repelled the assault, with only isolated successful hijackings occurring, and is assisting affected users. Similar attacks have impacted the entire telecom market since the start of the year, enabling fraudsters to access banking apps, government services, and other accounts tied to the number.