New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

A New Phishing Toolkit Emerges, Using Passkeys to Bypass Password Resets

Cybersecurity researchers have uncovered a sophisticated new phishing toolkit that uses passkeys to maintain access to compromised accounts even after password resets. iAuthFlow V2, a malware toolkit available on Russian-language cybercrime forums for $10,000, has been analyzed by Abnormal researchers, who have revealed its ability to evade standard security measures.

The tool works by creating a separate browser environment on the attacker’s server, which relays credentials and authentication responses from the victim’s browser. This allows the attacker to silently add a passkey to the compromised account, which can then be used for future access without needing the original password. When the victim discovers the compromise, a standard response is to change the password and revoke active sessions – but this does nothing to the new passkey, which remains under the attacker’s control.

The existence of iAuthFlow V2 highlights the rapidly improving sophistication of phishing techniques. The tool’s use of passkeys to bypass password resets demonstrates a level of technical expertise that was previously thought to be exclusive to nation-state actors. While Abnormal’s analysis is based on publicly available information from the seller’s forum posts and demonstrations, rather than actual use of the malware, it provides a chilling insight into the capabilities of modern phishing tools.

The implications of iAuthFlow V2 are significant. If this tool becomes widely adopted by cybercriminals, it could render traditional password reset procedures ineffective in combating phishing attacks. As Abnormal notes, changing passwords and revoking active sessions may no longer be sufficient to rectify a phisher’s compromise, as the passkey remains under attacker control.

While very little is known about iAuthFlow V2 beyond its publicly available documentation, its existence underscores the importance of staying ahead of emerging phishing threats. Cybersecurity professionals must remain vigilant in monitoring for signs of this tool and adapting their defenses to counter its capabilities. For individuals, it’s essential to be aware that a standard password reset may no longer be enough to protect against sophisticated phishing attacks.

Ultimately, iAuthFlow V2 serves as a reminder that the cat-and-mouse game between cybersecurity professionals and cybercriminals is ongoing. As attackers continually improve their techniques, defenders must stay one step ahead by adopting new strategies and staying informed about emerging threats.


Source: SecurityWeek — 2026-08-21