Skip to main content
Emerging Threats

ZeroTokens Phishing Platform Enables Real-Time Attack Adaptation

A cluttered office cubicle with laptop, phone, and papers, with a blurred cityscape in the background and a person's hand…

More than 45,000 phishing messages were sent to over 24,000 recipients across more than 700 organizations in a campaign built around a platform called ZeroTokens, Abnormal AI reported on August 25.

ZeroTokens: live operators steering sessions in real time

ZeroTokens is not a static phishing farmhouse where a single form collects data and dies. Abnormal AI observed a persistent WebSocket connection that relayed victims’ inputs to an operator console while allowing the operator to control which screen the victim saw next. The phishing site could present up to eight stages modeled on a financial institution’s verification process. As victims typed, the platform reported the session state, and a live operator chose subsequent prompts — from additional verification questions to alternate screens shown after failed verification attempts — keeping the interaction alive and adaptive.

The observed flow collected a broad set of sensitive items: login credentials, driver’s license and card details, SMS verification codes, app-based approvals and a separate trading password. After collection was complete, victims could be redirected to the legitimate institution’s website, leaving them unaware their interaction had been hijacked.

Technical plumbing: sender domains, SendGrid, and passing mail authentication

The campaign used ten sender domains and nine abused SendGrid accounts to dispatch messages. Abnormal AI noted that the messages passed SPF, DKIM and DMARC checks — meaning basic mail authentication checks would not necessarily flag them as fraudulent. The lure used a specific, believable pretext: W-8BEN tax-documentation reviews aimed at recipients with US securities holdings.

That combination — legitimate-looking send infrastructure, valid authentication records, and a financial tax-related pretext — helped craft messages that could more easily penetrate recipients’ inboxes and trust filters.

Scale and templates: banks, brokerages, and card issuers across regions

Abnormal AI’s analysis found the platform supported templates for 53 financial institutions and 36 card issuers, covering banks and brokerages in multiple regions. In aggregate, more than 45,000 messages reached over 24,000 recipients in more than 700 organizations; on the single peak day the researchers observed, about 24,000 messages were sent.

The breadth of templates and the multi-region coverage suggest the operation targeted customers of many distinct financial brands, tailoring phishing flows to appear institution-specific rather than generic.

Evidence points to an in-house criminal operation, not a rented service

Researchers reported that ZeroTokens’ console contained separate super-admin and operator roles. From that structure, Abnormal AI assessed with high confidence that ZeroTokens was likely an in-house tool used by a single criminal group rather than a phishing-as-a-service (PaaS) product rented to multiple gangs. The platform itself did not provide functionality for withdrawals, transfers, payee changes or trading orders.

Because ZeroTokens collected credentials and verification artifacts but did not execute financial transactions, Abnormal AI concluded that financial theft or payment redirection would most likely occur outside the platform using information harvested during the phishing interaction, rather than through ZeroTokens directly.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: Expect adversaries willing to combine legitimate-looking mail infrastructure with live-session control; detection approaches that rely solely on SPF/DKIM/DMARC may miss campaigns that pass those checks.
  • Affected enterprises and procurement leaders: The campaign used institution-specific templates and reproduced multi-stage verification flows, so brands should review how easily their customer journeys can be mirrored and consider where additional hard-to-replicate signals could be used to validate true sessions.
  • End users and the general public: The attackers used a concrete, plausible pretext — W-8BEN tax-documentation reviews — and then redirected victims back to the real site after harvesting credentials, increasing the chance victims never realize their data was stolen.

ZeroTokens combines three practical elements: believable pretexts, mail that passes authentication checks, and human-in-the-loop session steering. Abnormal AI’s finding that the platform lacks on-board transaction capability but supports a wide range of financial templates highlights a two-step criminal model — harvest data in real time, then use it off-platform to move money or access accounts. That architecture raises specific operational questions about how the harvested data was weaponized after collection and which institutions appeared in the platform’s templates; those are the next facts observers will need to trace the campaign’s full impact.

Original report