A new phishing platform known as ZeroTokens allows attackers to monitor victim sessions in real time and dynamically alter the prompts displayed, enabling adaptive attacks aimed at harvesting credentials and financial data. The platform provides operators with live visibility into information entered by victims, allowing them to steer individual phishing interactions while simultaneously using the collected data against legitimate institutions.
Abnormal AI published its analysis of the campaign on August 25, indicating that over 45,000 messages were distributed to more than 24,000 recipients across over 700 organizations. On a single peak day, approximately 24,000 messages were sent.
The campaign utilized ten sender domains and exploited nine SendGrid accounts. The phishing messages successfully passed SPF, DKIM, and DMARC authentication checks. The attackers employed a W-8BEN tax documentation review as a convincing pretext, targeting recipients with US securities holdings.
The phishing sites meticulously replicated the interfaces of targeted financial institutions, capable of presenting up to eight stages mirroring genuine verification processes. As victims input information, ZeroTokens relayed the session state to its platform, allowing an operator to choose the next screen to be displayed. The observed data collection flow included login credentials, driver’s license details, credit card information, SMS verification codes, app-based approvals, and a separate trading password.
A persistent WebSocket connection facilitated the relay of victim inputs to the operator console, simultaneously granting the operator control over the session. This capability also allowed operators to respond to failed verification attempts by presenting alternative prompts, thereby sustaining the phishing interaction instead of letting it terminate. Once data collection was complete, victims could be redirected to the legitimate institution's website.
ZeroTokens supports templates for 53 financial institutions and 36 card issuers, encompassing banks and brokerages across multiple regions. Abnormal AI's examination of the tool's console revealed distinct super-admin and operator roles. This structural design led researchers to conclude with high confidence that ZeroTokens is likely an in-house tool developed for a single criminal group, rather than a phishing-as-a-service (PaaS) offering available for rent.
The platform itself does not offer functionalities for withdrawals, transfers, payee changes, or trading orders. Consequently, Abnormal AI assessed that any financial theft or payment redirection would most likely occur outside the ZeroTokens platform, utilizing the information gathered during the phishing interaction, rather than through the platform directly.






