Hook, line, and vault: A technical deep dive into the 1Phish kit
ID: c97e0e22-6528-56e8-861b-1e13902f3b9b
STIX ID: report--c97e0e22-6528-56e8-861b-1e13902f3b9b
Feed Name: Datadog Security Labs
This report analyzes the "1Phish" phishing kit—an actively maintained, multi-stage phishing campaign that evolved between September 2025 and February 2026 to target 1Password users. Across four versions the kit progressed from a simple credential harvester to an MFA-aware, API-driven application that collects emails, secret keys, passwords, one-time codes, and recovery codes, uses advanced browser fingerprinting, bot scoring and cloaking services (HideClick), and exposes multiple malicious domains and IoCs for detection and takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
