PoisonSeed Phishing Kit Bypasses MFA to Steal Credentials from Users and Organizations
ID: 36766147-315b-5e75-bb0d-d52645020e20
STIX ID: report--36766147-315b-5e75-bb0d-d52645020e20
Feed Name: GBHackers
PoisonSeed is an active phishing kit (observed since April 2025) that targets Google, SendGrid, Mailchimp and similar services to perform AitM credential and MFA harvesting. The kit mimics legitimate UI elements (including a fake Turnstile challenge), appends encrypted victim emails for server-side validation, captures credentials, session cookies and API keys, and automates extraction of email lists for spam and cryptocurrency scams; the report provides technical breakdowns, infrastructure patterns (NICENIC-registered domains, Cloudflare hosting), defensive recommendations (phishing-resistant MFA, anomaly detection), and example IOC domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
