DomainTools security researchers have identified a fresh wave of malicious infrastructure linked to the PoisonSeed threat actor, with 21 domains registered since June 1, 2025, primarily targeting SendGrid customers and enterprise environments.
The campaign represents a continuation of sophisticated phishing operations that bear striking similarities to the notorious SCATTERED SPIDER cybercrime group.
The newly discovered domains follow established PoisonSeed tactics, techniques, and procedures (TTPs), utilizing fake Cloudflare CAPTCHA interstitials to add legitimacy before redirecting victims to credential harvesting pages.
Security researchers observed that these malicious domains display fabricated Cloudflare Ray ID data, mimicking legitimate security verification processes to deceive targeted users.
Technical Infrastructure and Registration Patterns
The malicious infrastructure demonstrates consistent registration and hosting patterns that align with previous PoisonSeed campaigns.
All identified domains were registered through the NiceNIC International Group Co. registrar, a provider frequently utilized by cybercriminals associated with “The Com” collective.
The domains are hosted on IP addresses assigned to Global-Data System IT Corporation (AS42624), specifically utilizing three primary hosting locations: 185.208.156.46, 86.54.42.106, and 185.196.10.54.
Domain naming conventions primarily spoof SendGrid services, incorporating terms like “loginportalsg,” “https-sendgrid,” and “mysandgrid” to impersonate legitimate email platform communications.
Additional domains reference generic digital services, including single sign-on (SSO) portals and AWS infrastructure, suggesting broader targeting beyond SendGrid customers.
URLScan.io analysis revealed that several domains successfully displayed fake Cloudflare CAPTCHA interstitials containing fraudulent Ray ID data, consistent with techniques documented in previous Mimecast threat research.
These interstitials serve as preliminary verification screens designed to establish credibility before directing victims to credential harvesting pages.
Connection to SCATTERED SPIDER Operations
The PoisonSeed campaign exhibits notable similarities with SCATTERED SPIDER operations, particularly in terms of infrastructure choices and social engineering methodologies.
Both threat actors maintain connections to “The Com,” a diverse cybercrime collective comprising primarily young, Western individuals who have been engaged in financially motivated attacks since 2022.
Recent SCATTERED SPIDER activities have targeted high-profile victims across multiple sectors, including retailers like Harrods, grocery chains, insurance providers, and airlines throughout the United States, United Kingdom, and Canada.
Several compromises resulted in significant business disruption, highlighting the operational sophistication of actors within this ecosystem.
Security researchers suggest that similarities between PoisonSeed and SCATTERED SPIDER operations may indicate current or historical affiliations within “The Com” collective.
The fluid nature of such cybercrime groups allows for membership changes over time, with former operators potentially establishing independent criminal enterprises while maintaining familiar TTPs.
DomainTools researchers have published several hundred additional domains with matching fingerprints on GitHub, enabling further community research and threat hunting activities.
Organizations utilizing SendGrid and similar email platforms should implement enhanced monitoring for suspicious authentication requests and verify communications through official channels before providing credentials.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates