Phishing toolkit registers passkeys to retain account access

Abnormal says iAuthFlow V2, a $10,000 phishing toolkit, can stealthily register attacker-controlled passkeys that let attackers access accounts after password resets.

Abnormal researchers reconstructed iAuthFlow V2 from seller posts and demonstrations and say the phishing toolkit can covertly register attacker-controlled passkeys to a victim’s account, allowing attackers to regain access after a password reset.

The toolkit first appeared on a Russian-language cybercrime forum. The base package is listed at $10,000, with additional modules sold separately. Abnormal reconstructed the toolkit’s operation from public seller material and demos and did not acquire or run the malware.

In Abnormal’s account, a successful phish directs a target to an attacker-controlled webpage where the victim enters credentials. A second, linked browser instance on the attacker’s server mirrors the victim’s interaction and completes authentication flows on the attacker’s side.

As the victim types, the toolkit logs entries and applies a device fingerprint to the victim’s browser. The relayed responses allow the remote browser to register a passkey-an authentication credential tied to the account-without the victim’s knowledge. After registration, the attacker can use the passkey from the remote environment even if the victim later resets the password or revokes active sessions.

“Changing the password and revoking active sessions are standard responses to a compromised mailbox. When an attacker’s access is limited to captured session cookies, those actions normally end that access,” Abnormal wrote. The company also noted that changing a password revokes some tokens and app passwords but does not remove passkeys because passkeys are credentials registered to the account rather than tokens derived from the password.

Abnormal emphasized that its analysis relies on seller posts and demonstrations rather than hands-on examination of an operational infection, so some technical details remain unconfirmed. Public descriptions of the toolkit vary and not all accounts mention the passkey feature. The toolkit’s price and modular sales model may limit its visible use.

Abnormal provided indicators of compromise and remediation guidance. The firm advised defenders to check accounts for unexpected registered credentials, review device and credential inventories, and revoke any suspicious passkeys or recently added authenticators.

Researchers noted the toolkit manipulates modern authentication flows and account-registered credentials to persist access after standard recovery actions.

Articles by this author