In recent months, cybersecurity researchers have noticed an increase in malicious domain registrations associated with an emerging cybercrime group known as PoisonSeed.

This group, first identified in April 2025, has focused its efforts on mimicking legitimate cloud-based email platforms (most notably SendGrid) to harvest business credentials.
By incorporating fake CAPTCHAs Cloudflare intermediate and Ray ID data into its phishing infrastructure, PoisonSeed has managed to evade surface detection and trick unsuspecting targets into handing over login information.
See also: L7 Botnet compromised 5.76 million devices for mass attacks
DomainTools analysts noted that between June and September 2025, PoisonSeed registered over twenty domains that mimicked SendGrid login gateways . These domains were often hosted on IP ranges assigned to Global-Data System IT Corporation (AS42624) and registered through NiceNIC International Group Co. , a registrar that has drawn criticism for its lax verification processes .
Researchers identified minor spelling variations and additional path structures—such as “sgportalexecutive[.]com” and “internal-sendgrid[.]com”—that were designed to exploit both user trust and automated inspection tools.
The impact of the PoisonSeed campaign extends beyond simple credential theft. Once enterprise credentials are compromised, the actor implements lateral movement within corporate environments to expand access. This progression can lead to data exfiltration, fraudulent money transfers, and even ransomware deployment.

In one incident, PoisonSeed leveraged the harvested credentials to send internal phishing invitations to high-value targets, ultimately exfiltrating sensitive financial data.
See also: Docker malware targets exposed APIs
Despite the sophistication of these campaigns, evasion of detection remains a key focus for PoisonSeed. By incorporating fake JavaScript-based CAPTCHAs and dynamically generated Ray IDs, the group evades detection. Furthermore, their use of co-hosting, on seemingly legitimate domains, adds an extra layer of stealth, delaying incident response teams from isolating the malicious infrastructure.
PoisonSeed: Infection mechanism and detection evasion
A closer look at PoisonSeed's infection mechanism reveals a multi-layered process that exploits human trust and automated filtering weaknesses. In the initial phase, victims receive an email purporting to come from SendGrid, with legitimate-looking headers and tracking links. When the target clicks on the link, they are redirected to a CAPTCHA page that appears authentic.
PoisonSeed embeds fake session tokens to maintain the illusion of authenticity. After validation, users are presented with a second form asking for SendGrid credentials. At this point, the team captures the submitted data before forwarding the victim to the legitimate SendGrid login page, minimizing suspicion.
See also: ZynorRAT targets Windows and Linux systems

The use of chained redirects and script obfuscation ensures that traditional URL blocklists and signature-based defenses struggle to keep up with the rapidly changing domain infrastructure. By constantly rotating domain names and leveraging compromised hosting environments, PoisonSeed maintains a resilient phishing operation that requires advanced threat intelligence and proactive monitoring.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The PoisonSeed case demonstrates a more worrying trend: phishing attacks are no longer “massive” and random, but are turning into targeted, well-crafted scenarios. The use of fake CAPTCHAs and Ray IDs are not just technical tricks, but a deliberate attempt to mimic the everyday user experience. This means that defenses based solely on filtering tools are no longer sufficient. Organizations are called upon to invest in real-time anomaly detection and strengthening policies zero trust, because the “authenticity” that the end user sees can be the most dangerous illusion.
