logo

Hook, line, and vault: A technical deep dive into the 1Phish kit

ID: c97e0e22-6528-56e8-861b-1e13902f3b9b

STIX ID: report--c97e0e22-6528-56e8-861b-1e13902f3b9b

Feed Name: Datadog Security Labs

Threat Score
78/100

Date Published: 2026-02-27

Date Updated: 2026-04-27

...
...

This report analyzes the "1Phish" phishing kit—an actively maintained, multi-stage phishing campaign that evolved between September 2025 and February 2026 to target 1Password users. Across four versions the kit progressed from a simple credential harvester to an MFA-aware, API-driven application that collects emails, secret keys, passwords, one-time codes, and recovery codes, uses advanced browser fingerprinting, bot scoring and cloaking services (HideClick), and exposes multiple malicious domains and IoCs for detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.