Suspicious 1Phish Kit Cookies and Telemetry Beacon

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the 1Phish kit fingerprint cookies validated_user_1pass and hideclick ignore alongside its base64 clid telemetry parameter. These constants are set by the phishing kit to track victim progress and evade automated crawlers. Requests carrying these kit-specific cookies or the clid telemetry marker identify pages served by the 1Phish infrastructure.

Related detections9 linkedT1539 — drag to rearrange
Suspicious 1Phish Kit Session API Harvesting Credentials and OTP
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Malicious Madgicx Plus Extension C2 Domain Resolution
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
Suspicious NFe-Themed Brazilian Lure Executable Execution
Malicious RemusStealer Credential Exfiltration to pics TLD C2
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Suspicious 1Phish Kit Cookies and Telemetry Beacon
Pivot detection · T1539 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.