PoisonSeed campaign hijacks business CRM and email accounts to send out huge amounts of spam

 PoisonSeed campaign hijacks business CRM and email accounts to send out huge amounts of spam

Published on April 7, 2025 | Category: tech

PoisonSeed campaign hijacks business CRM and email accounts to send out huge amounts of spam

News
By Sead Fadilpašić published

Stealing crypto wallets is the target, experts warn

Abstract image of cyber security in action.
OpenVPN-protokollet - därför är det så bra (Image credit: Shutterstock)

  • Hackers are targeting business CRM accounts to steal mailing lists
  • Emails used to send spam and trick people into setting up compromised crypto wallets
  • The goal is to steal the money, so be on your guard

Hackers are stealing mailing lists from major companies and using them to break into people’s cryptocurrency wallets and snatch their funds.

A new report from cybersecurity researchers Silent Push, who dubbed the campaign ‘PoisonSeed’, outlined how the criminals first set up spoofed landing pages for companies such as Coinbase, Ledger, Mailchimp, SendGrid, Hubspot, and others. They harvest people’s login credentials, which allow cybercriminals to log into mailing service accounts and exfiltrate any mailing lists.

Then they would send emails, impersonating those companies, and urging users to set up a new Coinbase Wallet, using the seed phrase embedded in the email. A seed phrase is a series of 12 to 24 words generated by the wallet that gives access to the funds inside. It acts as a master key, so anyone who has it can restore the wallet and control the cryptocurrencies inside.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Seed phrase poisoning attack

"Recipients of the bulk spam are targeted with a cryptocurrency seed phrase poisoning attack," Silent Push explained.

"As part of the attack, PoisonSeed provides security seed phrases to get potential victims to copy and paste them into new cryptocurrency wallets for future compromising."

Once users set up new wallets, and top them up with their funds, the criminals can simply send the money elsewhere, which is a permanent loss for the victims.

The researchers believe the campaign is the work of two “loosely aligned” threat actors, called Scattered Spider, and CryptoChameleon, both of which are reportedly part of a broader cybercrime ecosystem called The Com.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

Since cryptocurrency is permissionless and decentralized, once the funds are sent from one wallet to another, the only way to retrieve them is to have the other side send the money back.

In 2024, the US government has seized tens of millions of dollars' worth of crypto, as part of a broader investigation into market manipulation, theft, fraud, and more.

Via The Hacker News

You might also like

  • Hundreds of masterminds behind most pump-and-dump crypto coin schemes worldwide collect a staggering $250 million annually
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
A file and folder transferring data with a red warning mark indicating malware.

Kellogg reveals data breach, but it's lacking any real crunch

Abstract image of cyber security in action.

Massive Europcar data breach affects around 200,000 customers

Latest
BenQ PD2700U in a home office showing the Windows background

Windows 11’s rumored Start menu redesign could mean it eats up a huge chunk of desktop space for some users – although it can be tamed

See more latest
Most Popular
BenQ PD2700U in a home office showing the Windows background
Windows 11’s rumored Start menu redesign could mean it eats up a huge chunk of desktop space for some users – although it can be tamed
An Nvidia GeForce RTX 4060 Ti
Keen to buy an RTX 5060 Ti? Benchmarks and more rumored sightings suggest you don’t have long to wait for Nvidia’s next GPU
Tom Cruise swings from an aeroplane undercarriage in the final Mission Impossible movie
New Mission Impossible trailer shows off Tom Cruise's latest stunts in the final chapter of Paramount's action spy series
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, April 8 (game #1170)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, April 8 (game #667)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Tuesday, April 8 (game #401)
Walton Goggins and Aimee Lou Wood hug while on a beach
The White Lotus season 3 finale has Mike White already thinking of where the hit Max series should go next
Windows 11 logo
Windows 11 adoption grows as businesses finally get around to upgrading their devices
making tax digital
DOGE planning “hackathon” to build a “mega API” for accessing all IRS and taxpayer data
Y2K cast looking shocked
Max's #1 most-watched movie Y2K isn't the throwback I wanted – here are 3 better films to stream instead

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More