Breaking
SecurityDeveloping Story

Real-time phishing platform steers attacks

A phishing platform gives attackers live control over victim sessions, adapting prompts as credentials are harvested.

··55 minutes ago·3 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

A recently documented phishing operation has lifted the curtain on a style of attack that adapts as it unfolds. Dubbed ZeroTokens, the platform lets a live operator watch what a victim types and then change the next screen accordingly — turning a otherwise static phishing page into something that feels like a guided conversation.

Live operators shape each session

According to Abnormal AI's analysis published on August 25, the campaign sent more than 45,000 messages to over 24,000 recipients across more than 700 organizations. On a single peak day, around 24,000 messages were pushed out. The emails passed SPF, DKIM, and DMARC checks, lending them a veneer of legitimacy.

The attackers used ten sender domains and nine abused SendGrid accounts. Their pretext: a review of W-8BEN tax documentation, a form commonly required from US securities holders. That believable hook helped lure recipients into engaging with the phishing infrastructure.

Phishing site mimics real institutions

The phishing site reproduced the targeted financial institution's look and could present up to eight stages mirroring its verification process. As victims entered information, ZeroTokens relayed the session state to its platform, letting an operator choose which screen appeared next.

The observed flow collected login credentials, driver's license and card details, SMS verification codes, app-based approvals, and a separate trading password. A persistent WebSocket connection streamed the victim's inputs to the operator console, while also enabling the operator to steer the session.

Keeping the interaction alive

When a verification step failed, the operator could respond by showing another prompt, keeping the phishing session active rather than letting it end. That reactive approach gives attackers a way to ride out a victim's uncertainty and keep gathering data.

Once collection was complete, the victim could be redirected to the legitimate institution's website, adding a layer of misdirection that may help the attack go unnoticed until it's too late.

Scale points to in-house tooling

ZeroTokens supported 53 financial institutions and 36 card-issuer templates, covering banks and brokerages in multiple regions. That breadth suggests the operators had a wide net, but the tool's design points to a single criminal group behind it.

Abnormal AI found the console had separate super-admin and operator roles, leading researchers to assess with high confidence that this was likely in-house tooling for one group rather than a rented phishing-as-a-service (PaaS) offering.

Platform itself doesn't move money

The platform did not provide functionality for withdrawals, transfers, payee changes, or trading orders. Instead, Abnormal assessed that financial theft or payment redirection would most likely occur outside the platform, using the information collected during the phishing interaction.

That separation likely lets the operators keep their tooling focused on data collection, while the actual theft happens elsewhere—maybe through the genuine institution's own systems once the harvested credentials are used.

Why it matters

This kind of adaptive phishing could raise the bar for detection. Traditional defenses often rely on spotting static indicators—a certain URL, a particular template. But when an operator can change the attack midstream based on a victim's inputs, those signatures become less reliable.

For businesses and individuals, the lesson is that even well-crafted emails that pass authentication checks can carry a live threat. The use of W-8BEN tax forms as a pretext is a reminder that attackers will tailor lures to specific financial contexts, and the ability to present multiple verification steps means a single slip could expose a cascade of sensitive data.

#phishing#zerotokens#abnormal-ai#cybercrime#credential-theft

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories