logo

PoisonSeed Phishing Kit Bypasses MFA to Steal Credentials from Users and Organizations

ID: 36766147-315b-5e75-bb0d-d52645020e20

STIX ID: report--36766147-315b-5e75-bb0d-d52645020e20

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2025-08-12

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

PoisonSeed is an active phishing kit (observed since April 2025) that targets Google, SendGrid, Mailchimp and similar services to perform AitM credential and MFA harvesting. The kit mimics legitimate UI elements (including a fake Turnstile challenge), appends encrypted victim emails for server-side validation, captures credentials, session cookies and API keys, and automates extraction of email lists for spam and cryptocurrency scams; the report provides technical breakdowns, infrastructure patterns (NICENIC-registered domains, Cloudflare hosting), defensive recommendations (phishing-resistant MFA, anomaly detection), and example IOC domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.