Find notable cyber news and cases, enriched with sources, timelines, and signals.

ZeroTokens real-time phishing campaign

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The ZeroTokens phishing campaign is steering victim sessions in real time, raising the chance that credentials and financial information are captured across more than 700 organizations. Operators can monitor what victims enter and change the next prompt while keeping the session active through failed verification attempts. The operation uses a believable W-8BEN tax-documentation lure and infrastructure that passes SPF, DKIM, and DMARC checks.

Related Happenings

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover

Threat Actor Meta
H score37 First: 20.02.2026 22:00 Last: 20.02.2026 22:00 Sources 1

About this happening: A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...

Timeline

  1. 25.08.2026 17:30 2 articles · 2h ago

    Abnormal AI details ZeroTokens real-time phishing platform

    Initial Disclosure

    Abnormal AI published analysis of ZeroTokens, a phishing platform that gives operators live visibility into victim sessions and lets them change prompts in real time while harvesting credentials and financial information. The campaign used ten sender domains and nine abused SendGrid accounts, passed SPF, DKIM and DMARC checks, relied on a W-8BEN tax-documentation lure, and supported 53 financial institutions and 36 card-issuer templates across more than 700 organizations.

    Show sources