ZeroTokens phishing kit targets 53 banks

Published August 25, 2026

A phishing platform called ZeroTokens lets criminals watch victims type their bank details live and change what appears on screen next. Researchers say it has already been used to target customers of 53 banks and brokerages with fake tax-form emails.

Report priority
Medium
Targets
SendGrid

How it works

Attackers send emails that pass normal spam and authenticity checks, posing as a W-8BEN tax form review, and link to a fake copy of the victim's bank or brokerage site that can show up to eight verification screens while a live operator watches and steers each step.

What to do

If you hold US securities and recently received an unexpected email asking you to review or confirm a W-8BEN tax form, treat it as suspicious rather than clicking through.

Do not enter banking credentials, ID, card numbers, or verification codes on a page reached from an unsolicited tax-document email, go to your bank or brokerage directly by typing its known address, and report the email to your provider. ZeroTokens itself cannot move money, but criminals can use anything you type into it to log in or commit fraud elsewhere.

Technical details

Affected software: SendGrid

A recipient with US securities holdings gets an email that looks like a routine W-8BEN tax document review and passes their email provider's authenticity checks. They click through to a site built to look exactly like their bank or brokerage, which asks for a login, then a driver's license and card details, then an SMS code, an app approval, and finally a separate trading password. Behind the scenes a live operator watches each answer arrive over a persistent connection and picks which screen to show next, and if a verification code fails, the operator can serve another prompt instead of ending the session.

Abnormal AI documented a phishing kit, ZeroTokens, used from ten sender domains and nine abused SendGrid accounts, with mail passing SPF, DKIM and DMARC. Its lure was a W-8BEN tax-documentation review aimed at holders of US securities. The kit renders up to eight verification screens cloned from a targeted institution and streams victim input to an operator console over a persistent WebSocket, letting a human operator pick the next screen or re-prompt after a failed code, effectively running the session live rather than as a static fake page.

Separate super-admin and operator roles in the console led researchers to assess it as likely in-house tooling for one group rather than phishing-as-a-service. The platform itself has no transfer, withdrawal, or trading functions; any resulting fraud would happen outside it using the harvested credentials, ID, card, code, and trading-password data.