A malicious campaign dubbed PoisonSeed exploits compromised credentials associated with customer relationship management (CRM) tools and bulk email providers to send spam containing Seed Phrase Poisoning , with the aim of emptying victims' digital wallets
See also: What are whale-phishing attacks and how to protect yourself

PoisonSeed's targets include business organizations and individuals outside the cryptocurrency industry. Among the cryptocurrency companies affected are Coinbase and Ledger, as well as bulk email providers such as Mailchimp, SendGrid, Hubspot, Mailgun , and Zoho.
The activity is assessed as distinct from two loosely connected malicious actors, Scattered Spider and CryptoChameleon, which belong to a broader cybercrime ecosystem called The Com. Some aspects of the campaign were previously revealed by security researcher Troy Hunt and Bleeping Computer last month.
The attacks involve the malicious actors creating fake phishing for well-known CRM and bulk email companies, aiming to trick high-value targets into providing their credentials. Once the credentials are obtained, the hackers proceed to create an API key to ensure continued access, even if the owner changes the password.
See also: GitHub supply chain attack detected in SpotBugs tokens
In the next phase, the operators extract mailing lists, possibly using an automated tool, and send spam from these compromised accounts. The spam emails originating from the supply chain after the CRM breach inform users that they need to create a new Coinbase wallet using the recovery phrase embedded in the email.

The ultimate goal of the attacks is to use the same recovery phrase to take over accounts and transfer funds from those wallets. The links to Scattered Spider and CryptoChameleon come from the use of a domain (“mailchimp-sso[.]com”) previously identified as being used by the former, as well as CryptoChameleon’s historical targeting of Coinbase and Ledger.
However, the phishing kit used by PoisonSeed bears no resemblance to those used by the other two threat groups, which raises the possibility that this is either a brand new phishing kit from CryptoChameleon or a different threat actor that simply uses similar tactics.
This development comes as a Russian-speaking malicious actor using phishing pages hosted on Cloudflare Pages.Dev and Workers.Dev to distribute malware that can remotely control infected Windows systems. A previous version of the campaign was also found to be spreading the StealC.
See also: Cyberattacks on water and electricity companies are devastating
Seed Phrase Poisoning attacks refer to an attack technique in the world of cryptocurrency and wallet security. A seed phrase is a string of words used to create and retrieve a cryptocurrency wallet . Specifically, a Seed Phrase Poisoning attack aims to mislead the user during the process of creating or storing the seed phrase.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
