Key Insights
Abnormal's threat intelligence team discovered and analyzed ZeroTokens, a multi-brand financial phishing platform built around live control of each target interaction. This report exposes the platform behind the phishing, not just individual lure sites.
In the Australian CommSec wave, messages sent through abused SendGrid accounts passed SPF, DKIM, and DMARC checks, and the lure relied on a real tax documentation requirement. A message can look legitimate at delivery and still lead into a sophisticated, human-controlled phishing operation.
What You'll Learn in the Report
How a single session can collect credentials, SMS codes or app approvals, driver's license details, and a Trading Password, and why the response needs to go beyond a password reset.
Why SMS codes, email codes, and push approvals can be collected while they're still valid, while FIDO2/WebAuthn security keys and passkeys can't be relayed the same way.
Which platform-level signals and indicators of compromise (IOCs) survive the rotation of disposable sender domains and lure hosts.
When a malicious email is blocked before it reaches the inbox, the live operator never gets a chance to engage. Abnormal's Behavioral AI evaluates whether a message fits normal communication patterns, rather than treating clean authentication as proof it's safe.
Download your version of the report with the form above.
Earn ISC2 CPE (1 credit)
This resource is ISC2 CPE eligible. Submit the credit form to claim your continuing-education credits.
