New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Sophisticated Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

A new phishing toolkit has emerged, showcasing the rapidly advancing capabilities of cybercriminals. iAuthFlow V2, a malware tool sold on Russian-language cybercrime forums for $10,000, allows attackers to maintain access to victims’ accounts even after password resets.

The toolkit’s primary mechanism is a “passkey” module that enables attackers to use a registered credential, rather than a token derived from the victim’s password. This means that once an attacker has successfully phished a passkey, they can use it to regain access to the account without needing to know the original password. The process is made possible by the toolkit’s ability to silently add a ready-made passkey to the victim’s browser and relay authentication responses to the attacker-controlled server.

In a typical phishing scenario, a victim who discovers their account has been compromised would change their password and revoke active sessions, effectively cutting off the attacker’s access. However, iAuthFlow V2 subverts this process by using a registered credential that is not affected by password resets or session revocations. This allows attackers to maintain a foothold in the victim’s account, enabling them to “try another way” at login and use the passkey without needing to know the original password.

Abnormal researchers have analyzed the toolkit based on publicly available information from the seller’s forum posts and demonstrations. While the analysis is not definitive, it provides valuable insights into the capabilities of iAuthFlow V2 and highlights the increasing sophistication of social engineering technology.

The emergence of iAuthFlow V2 serves as a reminder that password resets are no longer sufficient to rectify phishing compromises. As cybercriminals continue to push the boundaries of what is possible with phishing attacks, it’s essential for individuals and organizations to adopt more robust security measures, such as two-factor authentication and regular account monitoring.

Ultimately, iAuthFlow V2 represents a significant escalation in the cat-and-mouse game between attackers and defenders. Its existence underscores the need for cybersecurity professionals to stay vigilant and adapt their strategies to counter emerging threats. By doing so, they can help protect individuals and organizations from these sophisticated phishing attacks and prevent the loss of sensitive information.

Practical takeaway: To minimize the risk of being compromised by iAuthFlow V2 or similar toolkits, it’s essential to implement robust security measures such as two-factor authentication, regular account monitoring, and password managers. Users should also be cautious when interacting with suspicious emails or websites and report any potential phishing attempts to their IT department or authorities immediately.


Source: SecurityWeek — 2026-08-21