Suspicious 1Phish Kit Session API Harvesting Credentials and OTP

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects requests to the 1Phish kit session API paths that collect credentials, one-time passcodes, and recovery codes from victims. The kit exposes structured api session endpoints keyed by session id to stage each stolen factor as the phishing flow progresses. Traffic to these session credential, otp, and recovery routes indicates an active 1Phish deployment harvesting authentication material.

Related detections9 linkedT1566.002 — drag to rearrange
Suspicious 1Phish Kit Cookies and Telemetry Beacon
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
Suspicious NFe-Themed Brazilian Lure Executable Execution
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
Malicious Credential Harvesting Request via All-in-1 PHP Endpoint (via proxy)
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Suspicious 1Phish Kit Session API Harvesting Credentials and OTP
Pivot detection · T1566.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.