216.73.216.233

Inside a phishing panel

· Published 11/05/2026 08:50 · Modified 11/05/2026 09:56

Export JSON

Essential information

Published
11/05/2026 08:50
Modified
11/05/2026 09:56
Tags
2026-05-11 adversary-in-the-middle aitm cryptocurrency exchange targeting doko panel identity provider compromise phishing panel real-time phishing session hijacking vishing
Related entities
5 observables, 1 intrusion sets (apt), 22 others

Description

Security researchers gained direct access to Doko's Panel, a platform used in criminal campaigns by ShinyHunters and BlackFile groups. The investigation revealed four distinct infrastructure clusters operating independently customized variants of the tooling. Attacks combine voice phishing with techniques targeting enterprise identity providers like Okta, Microsoft, and Google, as well as cryptocurrency exchanges. Operators call victims impersonating IT helpdesk staff, directing them to combosquatted domains where credentials and MFA tokens are manually relayed in real-time. Confirmed breaches include SoundCloud (30M records), Match Group (10M records), Betterment (20M records), and Crunchbase. Over 400 domains have been identified linked to these operations. Evidence shows extensive use of AI language models in developing phishing infrastructure, with operators leveraging legitimate services to rapidly deploy and rotate attack infrastructure.

External references