Your Daily Dose of Domain Trends & Insights

Domain Today – Categories

Explore Domain Today

PoisonSeed Expands Credential Theft Operations with New Domains

PoisonSeed, a notorious threat actor, has intensified its operations by leveraging new domains to enhance credential theft activities. Since June 1, 2025, DomainTools Investigations have flagged 21 recently registered domains associated with PoisonSeed. While specific targets remain undisclosed, the actor’s historical focus on cryptocurrency platforms and corporate environments accentuates the critical need for vigilance.

WUUK Outdoor Security Camera Wireless, 4-Cams Kit, 2K Home Security System with Base Station, 32GB Local Storage, No Month...

WUUK Outdoor Security Camera Wireless, 4-Cams Kit, 2K Home Security System with Base Station, 32GB Local Storage, No Month… | $499.99

These domains, registered through the NiceNIC International Group Co. registrar and hosted on IP addresses linked to Global-Data System IT Corporation (AS42624), contain references to SendGrid and generic digital services like single sign-on portals and login pages. Notable examples include https-loginsg[.]com, sgaccountsettings[.]com, and my-sandgrid[.]com.

ZOSI 3K Lite Security Camera System Indoor Outdoor,AI Human/Vehicle Detection,Night Vision,Remote Access,4pcs 1080P 1920TV...

ZOSI 3K Lite Security Camera System Indoor Outdoor,AI Human/Vehicle Detection,Night Vision,Remote Access,4pcs 1080P 1920TV… | $169.99

DomainTools investigators have shared a comprehensive list of hundreds of domains exhibiting similar registration and hosting characteristics on their GitHub repository, aiding threat hunters and analysts in identifying potential risks.

Arlo Essential 2K Outdoor Security Camera (2nd Generation) – 4 Pack – Outdoor & Indoor Wireless Camera, Integrated Spotlig...

Arlo Essential 2K Outdoor Security Camera (2nd Generation) – 4 Pack – Outdoor & Indoor Wireless Camera, Integrated Spotlig… | $399.00

A key element of PoisonSeed’s strategy involves deploying fake Cloudflare CAPTCHA challenges to deceive visitors. These malicious domains present interstitial pages resembling authentic Cloudflare Ray ID verification screens, complete with fabricated Ray ID strings, aiming to lower user suspicion before redirecting them to phishing sites soliciting enterprise credentials.

HD 2.7K 5.0MP with Audio Outdoor Wired Security Camera Systems PoE Outdoor Surveillance Video System

HD 2.7K 5.0MP with Audio Outdoor Wired Security Camera Systems PoE Outdoor Surveillance Video System | $299.99

Upon harvesting credentials, PoisonSeed operatives are likely to exploit them for subsequent phishing endeavors, lateral movement within compromised corporate networks, or unauthorized entry into cryptocurrency accounts. Previous campaigns have showcased PoisonSeed’s adeptness in combining brand impersonation with social engineering to execute large-scale cryptocurrency extortion via SendGrid-themed phishing.

Swann AdvancedX™ 4K Wired NVR Security Camera System, 8 Channels, 4 Outdoor PoE Cameras, 1TB Hard Drive Storage, Color Nig...

Swann AdvancedX™ 4K Wired NVR Security Camera System, 8 Channels, 4 Outdoor PoE Cameras, 1TB Hard Drive Storage, Color Nig… | $129.95

Notably, PoisonSeed’s tactics closely align with those attributed to the SCATTERED SPIDER adversary group, known for targeting various sectors across the U.S., U.K., and Canada with disruptive and data theft incidents. While direct evidence linking PoisonSeed’s new domains to SCATTERED SPIDER’s breaches is lacking, shared methodologies like fake CAPTCHA interstitials and domain naming conventions suggest a potential operational connection between the two groups.

MWRCTV 4K Security Camera System,4pcs Wired 8MP Dome IP PoE Cameras for Home Security,110° Wide Angle Lens,2-Way Audio,Sma...

MWRCTV 4K Security Camera System,4pcs Wired 8MP Dome IP PoE Cameras for Home Security,110° Wide Angle Lens,2-Way Audio,Sma… | $298.99

SCATTERED SPIDER, a part of “The Com” collective, comprises financially motivated cybercriminals specializing in smishing, SIM-swap fraud, and MFA-fatigue attacks. The evolution of PoisonSeed’s techniques may stem from collaboration or turnover within “The Com,” indicating a possible transfer of core tactics from SCATTERED SPIDER to PoisonSeed.

The emergence of PoisonSeed’s infrastructure underscores the increasing sophistication of eCrime actors in credential theft. Security teams are advised to monitor NiceNIC-registered domains referencing SendGrid or SSO, scrutinize inbound traffic for Cloudflare CAPTCHA interstitials from unfamiliar domains, block or redirect known PoisonSeed domains and associated IP addresses, and reinforce multi-factor authentication protocols alongside user-awareness training on CAPTCHA impersonation.

Continuous threat intelligence sharing and collaborative monitoring are paramount in thwarting PoisonSeed’s efforts to compromise enterprise credentials and minimize subsequent repercussions.

Mayura Kathir, a cybersecurity reporter at GBHackers News, covers a range of daily incidents, including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

📰 Related Articles


📚Book Titles