logo

Shedding Light on PoisonSeed’s Phishing Kit

ID: 4cddc853-593f-5b5f-a866-411ca03982ec

STIX ID: report--4cddc853-593f-5b5f-a866-411ca03982ec

Feed Name: NVISO Labs

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-28

Author: Efstratios Lontzetidis

...
...

NVISO details an active PoisonSeed phishing campaign that uses a React-based, MFA-resistant phishing kit to perform precision-validated phishing and Adversary-in-the-Middle capture of credentials, 2FA (authenticator, SMS, email, API keys) and authentication cookies to bypass MFA and take over CRM/bulk-email accounts. The report includes code-level analysis of the fake Cloudflare Turnstile flow, infrastructure (registrar, hosting, name servers), a long list of IoCs, hunting queries, and mitigation advice (phishing-resistant MFA, user awareness, and anomaly detection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.