PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack
ID: 5b847beb-80fb-5fdd-8e7d-9f3086bb2ad2
STIX ID: report--5b847beb-80fb-5fdd-8e7d-9f3086bb2ad2
Feed Name: GBHackers
PoisonSeed is a supply-chain style phishing campaign that compromises CRM and bulk email provider accounts to export mailing lists and send large-scale phishing messages which deliver attacker-provided cryptocurrency seed phrases; victims who use those poisoned seed phrases create wallets attackers can later access. The campaign has been linked to more than 49 domains via WHOIS and phishing-kit fingerprints and includes a documented compromise of Akamai's SendGrid account used to send Coinbase-themed phishing lures. Organizations are advised to monitor IOCs for related domains/IPs and harden email and API security to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
