Threat Advisory

PoisonSeed MFA-Resistant Phishing Campaign

Threat: Phishing Campaign
Threat Actor Name: PoisonSeed
Targeted Region: Global
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

PoisonSeed is a phishing actor linked to the broader “The Com” cybercrime network, sharing similarities with Scattered Spider and CryptoChameleon but operating independently. Its campaigns focus on compromising CRM and bulk email accounts to steal contact lists and conduct cryptocurrency-related scams. Victims are tricked into using attacker-controlled seed phrases in new wallets, enabling theft later. Notable incidents include phishing against Troy Hunt’s Mailchimp account and Coinbase users. NVISO’s research, building on earlier findings, confirms the group has been running an MFA-resistant phishing kit in active campaigns.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

PoisonSeed is a phishing actor linked to the broader “The Com” cybercrime network, sharing similarities with Scattered Spider and CryptoChameleon but operating independently. Its campaigns focus on compromising CRM and bulk email accounts to steal contact lists and conduct cryptocurrency-related scams. Victims are tricked into using attacker-controlled seed phrases in new wallets, enabling theft later. Notable incidents include phishing against Troy Hunt’s Mailchimp account and Coinbase users. NVISO’s research, building on earlier findings, confirms the group has been running an MFA-resistant phishing kit in active campaigns.[emaillocker id="1283"]

PoisonSeed delivers spear-phishing emails impersonating trusted services, embedding encrypted victim emails in malicious URLs for targeted validation. Victims encounter a fake Cloudflare Turnstile challenge, which secretly verifies the embedded email before serving a realistic login form. Credentials are captured and forwarded to both the attacker and the real service in real time an Adversary-in-the-Middle (AiTM) approach. The kit also harvests second-factor authentication data like SMS codes or app tokens, enabling full account compromise through stolen session cookies. Infrastructure is tied to NICENIC registrations, Cloudflare hosting, and DNS from Cloudflare and Bunny.net.

Defenders can detect PoisonSeed activity by monitoring for suspicious domains, unusual Turnstile prompts, and URLs containing encrypted email strings. Recommended countermeasures include phishing-resistant authentication, enhanced anomaly detection for logins and 2FA, and user training to spot phishing cues. Network monitoring for domain registrations following known PoisonSeed patterns can provide early warning. NVISO’s analysis offers actionable detection and hunting tips, combining infrastructure tracking with user awareness to help security teams prevent and respond to these AiTM phishing campaigns

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Reconnaissance T1593 Search Open Websites/Domains Search Engines
Resource Development T1583.001 Acquire Infrastructure Domains
Initial Access T1566.002 Phishing Spearphishing Link
Credential Access T1110.002 Brute Force Password Guessing
T1556.004 Modify Authentication Process Network Device Authentication
Collection T1114.002 Email Collection Remote Email Collection
T1119 Automated Collection
Command and Control T1071.001 Application Layer Protocol Web Protocols
Impact T1530 Data from Cloud Storage

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu