Friday, 21 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

The Register ·
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

A phishing kit for sale on Russian-language cybercrime forums claims it can enroll attacker-controlled passkeys on compromised accounts, providing persistent access after passwords are changed.

Advertised at around $10,000 for the base package, with additional modules sold separately, iAuthFlow v2 aims to solve a common problem for attackers: being locked out after the victim detects the compromise.

Defenders would ordinarily revoke session tokens and rotate credentials.

Those measures remain necessary, but may not be sufficient if the attacker has enrolled a passkey on the compromised account.

According to Abnormal Security, which examined the kit's documentation and demonstration videos, the technique uses a browser-in-the-middle (BitM) model involving two separate browser environments.

In a BitM attack, the victim appears to complete the login on their own device, while the attacker's infrastructure relays the interaction through a separate browser session.

The victim sees a phishing page impersonating the targeted service.

The iAuthFlow v2 demos focused on Google, but the seller advertises packages for iCloud, LinkedIn, and Microsoft too.

The victim enters their account details into the phishing page, while iAuthFlow v2 operates a separate browser on the attacker's server.

It sends the victim's input to Google and relays Google's prompts back to the victim.

The process repeats until the authentication flow is complete.

Once authentication is complete, iAuthFlow v2 controls an authenticated browser session and uses it to enroll an attacker-controlled passkey, Abnormal says.

That credential can remain valid after the victim changes their password.

Rather than sending the victim to their Gmail inbox after authentication, iAuthFlow v2 displays a brief loading screen reading: "Verification, Processing." Meanwhile, the toolkit works behind the scenes to register a passkey to an attacker-controlled device.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›