EXECUTIVE SUMMARY:
PoisonSeed is a phishing actor linked to the broader “The Com” cybercrime network, sharing similarities with Scattered Spider and CryptoChameleon but operating independently. Its campaigns focus on compromising CRM and bulk email accounts to steal contact lists and conduct cryptocurrency-related scams. Victims are tricked into using attacker-controlled seed phrases in new wallets, enabling theft later. Notable incidents include phishing against Troy Hunt’s Mailchimp account and Coinbase users. NVISO’s research, building on earlier findings, confirms the group has been running an MFA-resistant phishing kit in active campaigns.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
PoisonSeed is a phishing actor linked to the broader “The Com” cybercrime network, sharing similarities with Scattered Spider and CryptoChameleon but operating independently. Its campaigns focus on compromising CRM and bulk email accounts to steal contact lists and conduct cryptocurrency-related scams. Victims are tricked into using attacker-controlled seed phrases in new wallets, enabling theft later. Notable incidents include phishing against Troy Hunt’s Mailchimp account and Coinbase users. NVISO’s research, building on earlier findings, confirms the group has been running an MFA-resistant phishing kit in active campaigns.[emaillocker id="1283"]
PoisonSeed delivers spear-phishing emails impersonating trusted services, embedding encrypted victim emails in malicious URLs for targeted validation. Victims encounter a fake Cloudflare Turnstile challenge, which secretly verifies the embedded email before serving a realistic login form. Credentials are captured and forwarded to both the attacker and the real service in real time an Adversary-in-the-Middle (AiTM) approach. The kit also harvests second-factor authentication data like SMS codes or app tokens, enabling full account compromise through stolen session cookies. Infrastructure is tied to NICENIC registrations, Cloudflare hosting, and DNS from Cloudflare and Bunny.net.
Defenders can detect PoisonSeed activity by monitoring for suspicious domains, unusual Turnstile prompts, and URLs containing encrypted email strings. Recommended countermeasures include phishing-resistant authentication, enhanced anomaly detection for logins and 2FA, and user training to spot phishing cues. Network monitoring for domain registrations following known PoisonSeed patterns can provide early warning. NVISO’s analysis offers actionable detection and hunting tips, combining infrastructure tracking with user awareness to help security teams prevent and respond to these AiTM phishing campaigns
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-Technique |
| Reconnaissance | T1593 | Search Open Websites/Domains | Search Engines |
| Resource Development | T1583.001 | Acquire Infrastructure | Domains |
| Initial Access | T1566.002 | Phishing | Spearphishing Link |
| Credential Access | T1110.002 | Brute Force | Password Guessing |
| T1556.004 | Modify Authentication Process | Network Device Authentication | |
| Collection | T1114.002 | Email Collection | Remote Email Collection |
| T1119 | Automated Collection | — | |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Impact | T1530 | Data from Cloud Storage | — |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]