Phishing New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. By Kevin Townsend | August 21, 2026 (10:22 AM ET) Flipboard Reddit Whatsapp Whatsapp Email iAuthFlow V2 is a new phishing toolkit demonstrating the rapidly improving sophistication of phishing techniques. iAuthFlow V2 is a malware toolkit first seen on a Russian-language cybercrime forum. It is an advanced form of phishing that offers persistent access to the victimâs account, surviving a password reset. The base toolkit is offered for sale at $10,000, with additional modules available separately. Using available information from the sellerâs forum posts and demonstrations (but without acquiring or running the malware), Abnormal researchers have postulated an analysis of its operation, based on the âpasskeyâ module and employed against a Gmail account. The target is phished in the normal manner, landing on an attacker-controlled web page that is displayed in the targetâs browser. The attack requires the phish to be successful, and for the target to be fooled into entering credentials. However, unseen by the target, the attacker has a separate but connected second browser environment on the attackerâs own server. In the normal course of events, a compromise is detected either rapidly or eventually. Standard procedure for the victim is a password reset, which breaks the attackerâs access. But not if iAuthFlow V2 is the compromise method. As the target interacts with the primary phishing page, the credentials and authentication responses are relayed to the remote browser, which is what actually responds to the target. The malware immediately applies a device fingerprint to the targetâs browser. Each entry from the target is logged. The malware silently adds a ready-made passkey, and all is relayed to the second browser environment. Google, from the second browser but via the initial phishing page, asks the target to authenticate. If the initial phish is successful, the target will do so, but without knowing that this now includes authenticating the attacker-controlled passkey. Advertisement. Scroll to continue reading. When the victim discovers the compromise, a password reset and session revocation will normally cut off the attackerâs access â and is the standard response to a phishing compromise. âChanging the password and revoking active sessions are standard responses to a compromised mailbox. When an attackerâs access is limited to captured session cookies, those actions normally end that access,â explains Abnormal in its attack analysis. âGoogle also states that changing a password revokes app passwords and OAuth tokens with Gmail scopes, although some authorized devices and third-party connections may remain signed in.â But this process does nothing to the new passkey which is a credential registered to the account rather than a token derived from the password. It is now controlled by the attacker and can be used for future access. To regain access, the attacker need only âtry another wayâ at login and use the passkey without needing to know the password. It should be stressed that this analysis from Abnormal is based on the iAuthFlow V2 sellerâs online posts rather than actual use of the malware. Gemini describes the malware as âa commercial phishing-as-a-service (PhaaS) toolkit / framework marketed and sold to cybercriminals on underground hacking forums (such as the Exploit forum).â It makes no mention of passkeys. Copilotâs response is even more confused. So, it should be understood that very little is known about iAuthFlow V2. This lack of public knowledge of the toolkit is understandable given its cost and (if Abnormal has it right) stealthy operation. What its existence and Abnormalâs analysis does demonstrate, however, is the increasing sophistication of social engineering technology. Abnormalâs analysis includes IOCs and remediation advice. Fundamentally it suggests that a password reset is no longer sufficient to rectify a phisherâs compromise. Related : FBI, Google Dismantle âOutsider Enterpriseâ Phishing Service Related : MokN Raises $15 Million for Phish-Back Platform Related : Over 500 Organizations Hit in Years-Long Phishing Campaign Related : Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines â from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend CISO Conversations: Nico Waisman â From Self-Taught Hacker to AI-Driven Offensive Security at XBOW AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Stealthy âCity-Forumâ Attacks Target Salesforce and ServiceNow With Custom Toolset Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict CISO Conversations: Russ Kirby â Passion Is the Antidote to Burnout Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Latest News Critical Isolated-vm Vulnerability Leads to RCE on Host Rust Supply Chain Attack Linked to North Korean Hackers Contractorsâ CMMC Confidence Rises as Ability to Prove It Falls Behind Microsoft Patches Exploited Entra ID Vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Hackers Target Zimbra Servers in Active Exploitation Campaign Surveillance â Everything You Wanted to Know, But Were Afraid to Ask Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if itâs time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move UltraViolet Cyber has named Andrew Park Chief Information Security Officer. Glow has appointed Patti Degnan as Chief Information Security Officer. Daniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International. More People On The Move Expert Insights The AI Governance Gap Is a Leadership Problem: Waiting Wonât Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
A new phishing toolkit called iAuthFlow V2 enables persistent account compromise by silently registering an attacker-controlled passkey during a victim's authentication to a phishing page, allowing access to survive standard password resets and session revocations. The attack vector is a sophisticated phishing campaign where credentials and authentication responses are relayed to an attacker-controlled browser environment. No specific software versions are affected, as this is a toolkit targeting user behavior and authentication mechanisms; the primary workaround is user awareness training to detect phishing attempts and vigilance for unexpected passkey registration prompts.