Vishing Console + Fake CCleaner Trap Users

The Hacker News · High sophistication
Last updated August 17, 2026

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software download) that can be turned into realistic awareness simulations.

Key findings

  • Okta described “Work Panel,” a platform that helps criminals rapidly run vishing-driven account takeover campaigns (including domain registration, brand cloning, and launching phishing sites).
  • A fake CCleaner site (“ccleanerwind[.]top”) was reported delivering malware that installs a malicious Chrome extension (“GhostDesk”) to steal credentials and monitor victims.
  • An ongoing “City-Forum” campaign was reported stealing data via unauthenticated guest access in Salesforce Experience Cloud and ServiceNow portals (not primarily social engineering, but a notable data-theft operation).

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Service Desk, Finance, Executives, Developers.
  • Affected industries: Identity and access management (IdP), Software and cloud services, Telecommunications, Banking and financial services, Public sector portals, Consumers (Windows/Chrome users).
  • Attack channels: vishing, website.
  • Impersonated: Identity provider (IdP) support / security team, CCleaner download page (lookalike).

Awareness takeaways

  • Treat unexpected “security” phone calls as suspicious, and verify through a known, trusted channel (e.g., internal directory or vendor main support line).
  • Never follow a caller’s instructions to log in via a link/domain they provide; use known bookmarks or your company’s official login portal.
  • Only download software from official vendor sites or approved company app catalogs; be wary of lookalike domains.
  • If installing a tool unexpectedly modifies your browser or adds extensions, stop and report it, this can be spyware stealing passwords and screenshots.

Red flags to watch for

  • Unexpected security call pressuring immediate action
  • Caller directs you to a login page they provide
  • Request to share sign-in codes or complete login steps while on the phone
  • Non-official download domain (lookalike URL)
  • Installer triggers unexpected browser changes/extensions
  • Software prompts unusual permissions or installs add-ons without clear consent
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your phone rings, and a "security team" walks you straight into a fake login and spyware install in under two minutes. There’s a tool called Work Panel that lets criminals spin up vishing campaigns like a call center: one button to register a phishing domain, clone your company’s login, and launch a brand-new fake site in minutes. The script sounds like this: "Hi, this is the security team about suspicious sign-in activity." They give you a login link, watch you sign in, grab your codes, then send you to a fake CCleaner site like ccleanerwind.top that drops a GhostDesk Chrome extension to steal your passwords and screenshots. Your move: if anyone calls about “securing your account” and tells you where to log in or what to install, hang up and instead use your normal bookmark or our official portal to check your account yourself.

Similar attacks

Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Iranian Spies Lure Targets via WhatsApp to Drop Malware

Iranian Spies Lure Targets via WhatsApp to Drop Malware

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI…

September 16, 2026
Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026