ZeroTokens Enables Live Phishing Control

The ZeroTokens phishing platform gives attackers real-time visibility into victim sessions and lets them dynamically change prompts while stealing financial and authentication data. The campaign sent more than 45,000 emails to 24,000 recipients across over 700 organizations, using messages that passed SPF, DKIM, and DMARC checks. Operators could collect credentials, payment-card details, identity documents, SMS codes, app approvals, and trading passwords through institution-specific templates. Researchers assess that ZeroTokens is likely private tooling operated by a single cybercriminal group rather than a commercial phishing service.

Reference: infosecurity-magazine.com