ZeroTokens real-time phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The ZeroTokens phishing campaign is steering victim sessions in real time, raising the chance that credentials and financial information are captured across more than 700 organizations. Operators can monitor what victims enter and change the next prompt while keeping the session active through failed verification attempts. The operation uses a believable W-8BEN tax-documentation lure and infrastructure that passes SPF, DKIM, and DMARC checks.
Related Happenings
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor Meta
H score37
First: 20.02.2026 22:00
Last: 20.02.2026 22:00
Sources 1
About this happening:
A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor MetaAbout this happening: A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Timeline
-
25.08.2026 17:30 2 articles · 2h ago
Abnormal AI details ZeroTokens real-time phishing platform
Initial DisclosureAbnormal AI published analysis of ZeroTokens, a phishing platform that gives operators live visibility into victim sessions and lets them change prompts in real time while harvesting credentials and financial information. The campaign used ten sender domains and nine abused SendGrid accounts, passed SPF, DKIM and DMARC checks, relied on a W-8BEN tax-documentation lure, and supported 53 financial institutions and 36 card-issuer templates across more than 700 organizations.
Show sources
- ZeroTokens Phishing Platform Steers Attacks in Real Time — www.infosecurity-magazine.com — 25.08.2026 17:30
- ZeroTokens Phishing Platform Steers Attacks in Real Time — www.infosecurity-magazine.com — 25.08.2026 17:30