Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

DDoS Attack Hits Norwegian Government Services

August 27, 2026

Why “Shady AI” is Security’s Next Big Governance Problem

August 27, 2026

Your Firewall Benchmarks Are Reassuring, That’s the Problem

August 27, 2026
Facebook X (Twitter) Instagram
Thursday, August 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»ZeroTokens Phishing Platform Steers Attacks in Real Time
News

ZeroTokens Phishing Platform Steers Attacks in Real Time

Team-CWDBy Team-CWDAugust 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A phishing platform dubbed ZeroTokens allows attackers live visibility into victim sessions and the ability to change subsequent prompts in real time, allowing attacks to adapt in real time while targeting credentials and financial information.

The platform allowed an operator to monitor information entered by victims and steer individual phishing flows while separately using the harvested data against the genuine institution.

Abnormal AI published its analysis of the campaign on August 25. It found that more than 45,000 messages were sent to over 24,000 recipients across more than 700 organizations. Some 24,000 messages were sent on a single peak day, according to the research.

Live Operators Control Each Phishing Session

The campaign used ten sender domains and nine abused SendGrid accounts. Messages passed SPF, DKIM and DMARC checks and used W-8BEN tax-documentation reviews as a believable pretext for recipients with US securities holdings.

The phishing site reproduced the targeted financial institution and could present up to eight stages modeled on its verification process. As victims entered information, ZeroTokens reported the session state to its platform and allowed an operator to choose which screen appeared next.

The observed flow collected login credentials, driver’s license and card details, SMS verification codes, app-based approvals and a separate trading password. A persistent WebSocket connection relayed the victim’s inputs to the operator console while allowing the operator to control the session.

The operator could also respond to failed verification attempts by showing another prompt, keeping the interaction active rather than allowing the phishing session to end. Once collection was complete, the victim could be redirected to the legitimate institution’s website.

Read more on real-time phishing: Okta Flags Customized, Reactive Vishing Attacks Which Bypass MFA

Scale Suggests In-House Criminal Operation

ZeroTokens supported 53 financial institutions and 36 card-issuer templates, covering banks and brokerages in multiple regions.

Abnormal AI found the tool’s console had separate super-admin and operator roles, leading researchers to assess with high confidence that it was likely in-house tooling for a single group rather than a rented phishing-as-a-service (PaaS) offering.

The platform itself did not provide functionality for withdrawals, transfers, payee changes or trading orders. Abnormal therefore assessed that financial theft or payment redirection would most likely occur outside the platform using information collected during the phishing interaction, rather than through ZeroTokens itself.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Next Article Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Team-CWD
  • Website

Related Posts

News

DDoS Attack Hits Norwegian Government Services

August 27, 2026
News

Why “Shady AI” is Security’s Next Big Governance Problem

August 27, 2026
News

Average Cyber Insurance Losses Increase Despite Fewer Claims

August 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Don’t let “back to school” become “back to bullying”

September 11, 2025

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.