HomeSecurityPoisonSeed group registers new domains for credential theft

PoisonSeed group registers new domains for credential theft

In recent months, cybersecurity researchers have noticed an increase in malicious domain registrations associated with an emerging cybercrime group known as PoisonSeed.

PoisonSeed domains stealing credentials

This group, first identified in April 2025, has focused its efforts on mimicking legitimate cloud-based email platforms (most notably SendGrid) to harvest business credentials.

By incorporating fake CAPTCHAs Cloudflare intermediate and Ray ID data into its phishing infrastructure, PoisonSeed has managed to evade surface detection and trick unsuspecting targets into handing over login information.

See also: L7 Botnet compromised 5.76 million devices for mass attacks

DomainTools analysts noted that between June and September 2025, PoisonSeed registered over twenty domains that mimicked SendGrid login gateways . These domains were often hosted on IP ranges assigned to Global-Data System IT Corporation (AS42624) and registered through NiceNIC International Group Co. , a registrar that has drawn criticism for its lax verification processes .

Researchers identified minor spelling variations and additional path structures—such as “sgportalexecutive[.]com” and “internal-sendgrid[.]com”—that were designed to exploit both user trust and automated inspection tools.

The impact of the PoisonSeed campaign extends beyond simple credential theft. Once enterprise credentials are compromised, the actor implements lateral movement within corporate environments to expand access. This progression can lead to data exfiltration, fraudulent money transfers, and even ransomware deployment.

PoisonSeed group registers new domains for credential theft

In one incident, PoisonSeed leveraged the harvested credentials to send internal phishing invitations to high-value targets, ultimately exfiltrating sensitive financial data.

See also: Docker malware targets exposed APIs

Despite the sophistication of these campaigns, evasion of detection remains a key focus for PoisonSeed. By incorporating fake JavaScript-based CAPTCHAs and dynamically generated Ray IDs, the group evades detection. Furthermore, their use of co-hosting, on seemingly legitimate domains, adds an extra layer of stealth, delaying incident response teams from isolating the malicious infrastructure.

PoisonSeed: Infection mechanism and detection evasion

A closer look at PoisonSeed's infection mechanism reveals a multi-layered process that exploits human trust and automated filtering weaknesses. In the initial phase, victims receive an email purporting to come from SendGrid, with legitimate-looking headers and tracking links. When the target clicks on the link, they are redirected to a CAPTCHA page that appears authentic.

PoisonSeed embeds fake session tokens to maintain the illusion of authenticity. After validation, users are presented with a second form asking for SendGrid credentials. At this point, the team captures the submitted data before forwarding the victim to the legitimate SendGrid login page, minimizing suspicion.

See also: ZynorRAT targets Windows and Linux systems

PoisonSeed group registers new domains for credential theft

The use of chained redirects and script obfuscation ensures that traditional URL blocklists and signature-based defenses struggle to keep up with the rapidly changing domain infrastructure. By constantly rotating domain names and leveraging compromised hosting environments, PoisonSeed maintains a resilient phishing operation that requires advanced threat intelligence and proactive monitoring.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The PoisonSeed case demonstrates a more worrying trend: phishing attacks are no longer “massive” and random, but are turning into targeted, well-crafted scenarios. The use of fake CAPTCHAs and Ray IDs are not just technical tricks, but a deliberate attempt to mimic the everyday user experience. This means that defenses based solely on filtering tools are no longer sufficient. Organizations are called upon to invest in real-time anomaly detection and strengthening policies zero trust, because the “authenticity” that the end user sees can be the most dangerous illusion.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS