Researchers have uncovered iAuthFlow V2, a sophisticated phishing toolkit that uses stolen passkeys to maintain permanent account access, even after victims change their passwords.
- iAuthFlow V2 is a high-end phishing toolkit sold on underground forums for approximately $10,000.
- It exploits the 'Passkey' feature to register attacker-controlled credentials.
- Standard remediation, like password resets and session revocation, fails to remove the attacker's passkey access.
A new era of sophisticated cyberattacks has emerged with the discovery of iAuthFlow V2, an advanced phishing-as-a-service (PhaaS) toolkit. First spotted on Russian-language cybercrime forums, this malware is designed to provide attackers with persistent, long-term access to victim accounts, effectively rendering traditional security responses obsolete.
The core danger lies in how the toolkit manipulates the 'Passkey' authentication mechanism. While most users rely on passwords, passkeys are designed to be a more secure, passwordless alternative. However, iAuthFlow V2 weaponizes this very convenience against the user.
The Mechanics of the Attack
The attack begins with a standard phishing attempt where the victim is lured to a fraudulent website. As the victim enters their credentials, the toolkit—operating through a remote browser environment on the attacker's server—simultaneously performs a silent registration. It injects an attacker-controlled passkey into the victim's account (such as a Gmail account) without the user's knowledge.
Once this passkey is registered, the attacker no longer needs the user's password. Even if the victim detects the breach and follows standard protocol by changing their password and revoking all active sessions, the attacker's passkey remains valid and registered to the account.
Standard responses like changing a password are no longer sufficient to rectify a compromise if an attacker has registered a persistent passkey.
Why This Matters
BozokMedia analysis shows that the commercialization of such high-level toolkits marks a significant escalation in the cybercrime ecosystem. With a base price of $10,000, iAuthFlow V2 is a professional-grade weapon for cybercriminals. This development highlights a critical vulnerability in how modern authentication systems handle secondary credentials like passkeys during a compromise.
Frequently Asked Questions
Question 1: If I change my password, am I safe from iAuthFlow V2?
Not necessarily. If the attacker has successfully registered a passkey, they can use the 'try another way' option to log in despite your new password.
Question 2: How can I check if my account has been compromised this way?
You should immediately review your account's security settings, specifically looking for any 'Registered Passkeys' or 'Security Keys' that you did not personally authorize.