PoisonSeed is a phishing kit used in credential theft operations, particularly to steal credentials for email infrastructure and enterprise email-related services. The provided content describes it as MFA-resistant and capable of precision-validated credential theft. It is reported to focus on obtaining credentials for email infrastructure, which are then leveraged for follow-on phishing attacks. Multiple references indicate PoisonSeed has been used in campaigns spoofing SendGrid, with newly identified domains linked to the operation targeting SendGrid customers in an effort to compromise enterprise credentials. The content also states PoisonSeed has been used to exploit CRM accounts to launch cryptocurrency seed phrase poisoning attacks, and references YouTube-themed career phishing lures. One source in the content says the kit code was obtained and reversed, and that domain IOCs were provided for hunting, but the specific indicators are not included in the supplied material. The content does not provide malware hashes, IP addresses, or concrete victim lists. One mention claims PoisonSeed is allegedly leveraged by actors in “The Com,” but this attribution is presented as an allegation rather than established fact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign leveraging compromised CRM/bulk email accounts to send spam containing cryptocurrency seed phrases to drain wallets.
Post navigation ... PoisonSeed YouTube-themed Career Phishing
PoisonSeed is a phishing operation targeting enterprise credentials, primarily by spoofing SendGrid and using fake Cloudflare CAPTCHA interstitials to add legitimacy.
Phishing kit focused on stealing credentials for email infrastructure to enable follow-on phishing from compromised email environments; associated with actors in 'The Com' per the source.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.