Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PoisonSeed

Also known as: tracked as, Storm-2372, broader Midnight Blizzard operations, ditain, ditamine, echitenine, alstonamine, SkyCloak

Description

PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infrastructure for cryptocurrency-related spam. They utilize spear-phishing emails with malicious links, automate bulk downloading of email lists, and capture authentication cookies to bypass MFA. PoisonSeed has been linked to campaigns that exploit cross-device sign-in features and employ tactics such as cryptocurrency seed phrase poisoning. Their infrastructure includes domains registered through NICENIC and hosted on Cloudflare, with a focus on phishing CRM and bulk email provider credentials.

Goals & Targeting

Targeted Sectors

Financial services
Government
Healthcare
Telecommunications
Education
Defense
Energy
Critical infrastructure
Hospitality
Non profit
Pharmaceutical
Information technology
Media
Oil gas
Retail
Gaming
Nuclear
Aviation
Manufacturing
Legal services
Maritime
Mining
Utilities
Aerospace
Construction

Targeted Countries / Regions

CN
IR
GB
UA
IN
JP
PL
US
RU
IT
CA
KR
SG
RO
TR
ES
KP
MX
FR
TW
BR

AI Analysis

No AI analysis yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 1 Domain 17 IPv4 Address 2

References

  1. www.microsoft.com — Cited by web research for: Storm-2372
  2. pmc.ncbi.nlm.nih.gov — Cited by web research for: ditain
  3. www.varutra.com — Cited by web research for: Global
  4. phishingtackle.com — Cited by web research for: Troy
  5. www.silentpush.com — Cited by web research for: sso-account.com
  6. blogs.flinders.edu.au — Cited by web research for: flinders.okta.com

Intel Summary

2

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

Financial Targeting
Critical Infrastructure
Phishing

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.