$10K Phishing Kit Claims It Can Plant Rogue Passkeys for Persistent Access to Pwned Accounts
Abnormal Security says the $10,000 kit uses browser-in-the-middle sessions to add attacker-controlled passkeys that can survive password resets.
4 Articles
4 Articles
Phishers Plant Attacker Passkeys That Survive Password Resets
Passkeys arrived with bold claims. They would kill off phishing. No more reusable secrets to steal or reuse across sites. Google pushed them hard, with hundreds of millions of accounts now relying on the technology for login. Yet two distinct lines of research this month show how attackers already sidestep the protections in practice. One attack comes from commodity phishing kits sold on Russian forums. The other stems from careful reverse engin…
This new malware can use Google passkeys even after a victim resets their password
iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methodsSecurity researchers have discovered a new malware toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated…
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts
A phishing kit for sale on Russian-language cybercrime forums claims it can enroll attacker-controlled passkeys on compromised accounts, providing persistent access after passwords are changed. Advertised at around $10,000 for the base package, with additional modules sold separately, iAuthFlow v2 aims to solve a common problem for attackers: being locked out after the victim detects the compromise. Defenders would ordinarily revoke session toke…
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium






