LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
phishing

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands

zeroday.news ·

A new phishing platform known as ZeroTokens allows attackers to monitor victim sessions in real time and dynamically alter the prompts displayed, enabling adaptive attacks aimed at harvesting credentials and financial data. The platform provides operators with live visibility into information entered by victims, allowing them to steer individual phishing interactions while simultaneously using the collected data against legitimate institutions.

Abnormal AI published its analysis of the campaign on August 25, indicating that over 45,000 messages were distributed to more than 24,000 recipients across over 700 organizations. On a single peak day, approximately 24,000 messages were sent.

The campaign utilized ten sender domains and exploited nine SendGrid accounts. The phishing messages successfully passed SPF, DKIM, and DMARC authentication checks. The attackers employed a W-8BEN tax documentation review as a convincing pretext, targeting recipients with US securities holdings.

The phishing sites meticulously replicated the interfaces of targeted financial institutions, capable of presenting up to eight stages mirroring genuine verification processes. As victims input information, ZeroTokens relayed the session state to its platform, allowing an operator to choose the next screen to be displayed. The observed data collection flow included login credentials, driver’s license details, credit card information, SMS verification codes, app-based approvals, and a separate trading password.

A persistent WebSocket connection facilitated the relay of victim inputs to the operator console, simultaneously granting the operator control over the session. This capability also allowed operators to respond to failed verification attempts by presenting alternative prompts, thereby sustaining the phishing interaction instead of letting it terminate. Once data collection was complete, victims could be redirected to the legitimate institution's website.

ZeroTokens supports templates for 53 financial institutions and 36 card issuers, encompassing banks and brokerages across multiple regions. Abnormal AI's examination of the tool's console revealed distinct super-admin and operator roles. This structural design led researchers to conclude with high confidence that ZeroTokens is likely an in-house tool developed for a single criminal group, rather than a phishing-as-a-service (PaaS) offering available for rent.

The platform itself does not offer functionalities for withdrawals, transfers, payee changes, or trading orders. Consequently, Abnormal AI assessed that any financial theft or payment redirection would most likely occur outside the ZeroTokens platform, utilizing the information gathered during the phishing interaction, rather than through the platform directly.

phishingfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,

ddos

Massive DDoS attack disrupts Norway’s government digital services

A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]

breach

Hospital operator Nutex Health says data stolen in cyberattack

Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]

nation-state

Interpol targets Black Axe’s illicit financial web in latest international sting

The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents. The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.

ai security

Alice Secures $140M for AI Model Defense and Enterprise Security

Alice, formerly ActiveFence, has successfully raised $140 million in new funding, bringing its total investment to $280 million. The company plans to use these funds to enhance its defenses for AI models and bolster its enterprise security solutions.

patch

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]