<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PoisonSeed phishing campaign behind emails with wallet seed phrases in Threats</title>
    <link>https://community.isc2.org/t5/Threats/PoisonSeed-phishing-campaign-behind-emails-with-wallet-seed/m-p/78724#M1584</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A large-scale phishing campaign dubbed 'PoisonSeed' compromises&amp;nbsp;corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets.&lt;/P&gt;&lt;P&gt;According&lt;A href="https://www.silentpush.com/blog/poisonseed/" target="_blank" rel="nofollow noopener"&gt; to SilentPush&lt;/A&gt;, the campaign targets Coinbase and&amp;nbsp;Ledger using compromised accounts at Mailchimp, SendGrid, HubSpot, Mailgun, and Zoho.&lt;/P&gt;&lt;P&gt;The researchers link the campaign to recent incidents, such as the case of &lt;A href="https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/" target="_blank" rel="nofollow noopener"&gt;Troy Hunt's Mailchimp account&lt;/A&gt; compromise from late last month&amp;nbsp;and an &lt;A href="https://www.bleepingcomputer.com/news/security/coinbase-phishing-email-tricks-users-with-fake-wallet-migration/" target="_blank" rel="nofollow noopener"&gt;Akamai SendGrid account hack&lt;/A&gt; BleepingComputer reported in mid-March 2025, where the legitimate account was used to send out Coinbase seed phrase phishing emails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/poisonseed-phishing-campaign-behind-emails-with-wallet-seed-phrases/" target="_blank"&gt;https://www.bleepingcomputer.com/news/security/poisonseed-phishing-campaign-behind-emails-with-wallet-seed-phrases/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy reading - do you think cryptocurrency is still secure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
    <pubDate>Sat, 12 Apr 2025 04:02:58 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2025-04-12T04:02:58Z</dc:date>
    <item>
      <title>PoisonSeed phishing campaign behind emails with wallet seed phrases</title>
      <link>https://community.isc2.org/t5/Threats/PoisonSeed-phishing-campaign-behind-emails-with-wallet-seed/m-p/78724#M1584</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A large-scale phishing campaign dubbed 'PoisonSeed' compromises&amp;nbsp;corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets.&lt;/P&gt;&lt;P&gt;According&lt;A href="https://www.silentpush.com/blog/poisonseed/" target="_blank" rel="nofollow noopener"&gt; to SilentPush&lt;/A&gt;, the campaign targets Coinbase and&amp;nbsp;Ledger using compromised accounts at Mailchimp, SendGrid, HubSpot, Mailgun, and Zoho.&lt;/P&gt;&lt;P&gt;The researchers link the campaign to recent incidents, such as the case of &lt;A href="https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/" target="_blank" rel="nofollow noopener"&gt;Troy Hunt's Mailchimp account&lt;/A&gt; compromise from late last month&amp;nbsp;and an &lt;A href="https://www.bleepingcomputer.com/news/security/coinbase-phishing-email-tricks-users-with-fake-wallet-migration/" target="_blank" rel="nofollow noopener"&gt;Akamai SendGrid account hack&lt;/A&gt; BleepingComputer reported in mid-March 2025, where the legitimate account was used to send out Coinbase seed phrase phishing emails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/poisonseed-phishing-campaign-behind-emails-with-wallet-seed-phrases/" target="_blank"&gt;https://www.bleepingcomputer.com/news/security/poisonseed-phishing-campaign-behind-emails-with-wallet-seed-phrases/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy reading - do you think cryptocurrency is still secure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 04:02:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/PoisonSeed-phishing-campaign-behind-emails-with-wallet-seed/m-p/78724#M1584</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-04-12T04:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: PoisonSeed phishing campaign behind emails with wallet seed phrases</title>
      <link>https://community.isc2.org/t5/Threats/PoisonSeed-phishing-campaign-behind-emails-with-wallet-seed/m-p/78738#M1586</link>
      <description>&lt;P&gt;A great read, thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 07:39:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/PoisonSeed-phishing-campaign-behind-emails-with-wallet-seed/m-p/78738#M1586</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-04-12T07:39:00Z</dc:date>
    </item>
  </channel>
</rss>

