PoisonSeed is a financially motivated cybercrime threat actor active since at least March 2025 and associated with large-scale phishing, credential theft, session hijacking, and cryptocurrency theft. The group is known for targeting enterprise email and marketing platforms, cloud services, and cryptocurrency users, then abusing compromised accounts to expand follow-on phishing operations and monetize access. PoisonSeed has been linked to phishing campaigns against users of bulk email and CRM providers and to cryptocurrency-themed lures designed to steal wallet assets or manipulate victims into importing attacker-controlled seed phrases. Reported operations include compromise of legitimate email distribution infrastructure, export of mailing lists, creation of API keys for persistence, and reuse of trusted platforms to send high-volume phishing or scam messages. The actor has also been associated with career-themed phishing campaigns and social-engineering lures tailored to enterprise users. A defining characteristic of PoisonSeed is its use of polished adversary-in-the-middle phishing kits that spoof major service providers and validate targets in real time before presenting credential prompts. These kits have been described as React-based frameworks supporting credential capture, theft of MFA factors, and session cookie interception. Observed workflows include fake CAPTCHA or Turnstile-style interstitials, anti-bot delays, encrypted victim identifiers, server-side target validation, and relay of credentials and second-factor inputs to legitimate services. Supported MFA capture methods have included authenticator codes, SMS codes, email codes, and API keys. PoisonSeed has also been reported using an MFA-resistant phishing technique that abuses legitimate cross-device sign-in flows to sidestep the practical protection of FIDO2 security keys. In this approach, victims are tricked into approving an attacker-initiated login session by scanning a relayed QR code with a mobile authenticator application. Separate reporting also describes account-takeover activity in which attackers reset passwords and register their own FIDO key on compromised accounts. The actor’s tradecraft emphasizes scale, delivery reliability, and evasion. PoisonSeed has used compromised legitimate email and CRM infrastructure, spoofed login pages, cloud-hosted phishing infrastructure, rapid domain churn, and anti-analysis measures. Campaign reporting also notes overlap in tactics and infrastructure with Scattered Spider and CryptoChameleon, and some researchers place the activity in or near the broader English-speaking cybercriminal ecosystem often referred to as “The Com.” However, PoisonSeed is also treated by multiple researchers as a distinct cluster rather than a confirmed alias or sub-group of those actors. Primary victim sectors reported for PoisonSeed activity include financial services, information technology, enterprise cloud and email service providers, and cryptocurrency-related targets. The actor’s dominant motivation is financial gain through theft of credentials, session access, mailing lists, seed phrases, and downstream fraud or crypto theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
108 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possible match for the observed phishing tradecraft: large-scale credential theft via compromised SendGrid accounts, redirection through CAPTCHA pages, and use of lookalike SendGrid pages.
Likely responsible for a YouTube-themed career phishing campaign using Salesforce resources to deliver phishing emails, redirecting victims through tracking links to phishing landing pages with anti-analysis fake error pages, fake scheduling forms, and likely credential-harvesting login pages.
PoisonSeed is a financially motivated, Western-based eCrime group specializing in credential theft and phishing campaigns targeting enterprise and cryptocurrency sectors. They compromise bulk email/CRM providers to launch supply chain phishing, use advanced phishing kits for pixel-perfect spoofing, adversary-in-the-middle (AitM) proxies for MFA bypass, and seed phrase poisoning to steal cryptocurrency wallets. Their operations are characterized by rapid infrastructure churn, use of bulletproof hosting, and automation of email list exfiltration and API key creation.
PoisonSeed is a financially motivated threat actor specializing in phishing campaigns, particularly targeting enterprise credentials by spoofing trusted platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.