THE ZeroTokens phishing platform enables real-time attacks by providing operators with live visibility into victim sessions, allowing them to adjust prompts and collect sensitive information such as login credentials and financial data. Abnormal AI's analysis, published on August 25, revealed that over 45,000 messages were sent to 24,000 recipients across 700 organizations, with some phishing campaigns employing multiple sender domains and evading security checks.
The platform supports numerous financial institutions and is believed to be in-house tooling for a single criminal group rather than a phishing-as-a-service offering. It helps sustain phishing interactions by controlling the session flow, ultimately extracting valuable data for external exploitation.