Cybercriminals Offer $10K Phishing Kit to Plant Rogue Passkeys for Persistent Account Access
A new phishing kit, iAuthFlow v2, is being advertised on Russian-language cybercrime forums for approximately $10,000. This kit claims to enable attackers to enroll their own passkeys on compromised accounts, thereby maintaining persistent access even after victims change their passwords. The technique, identified by Abnormal Security, utilizes a browser-in-the-middle (BitM) attack model. In this method, the victim interacts with a phishing page impersonating a legitimate service (such as Google, iCloud, LinkedIn, or Microsoft), while the attacker's infrastructure relays the authentication process through a separate browser session. Once authentication is complete, iAuthFlow v2 uses the authenticated session to register an attacker-controlled passkey. This allows the attacker to bypass subsequent password changes and continue accessing the account. The kit's demonstration videos show the passkey being created within seconds of successful authentication, often during a brief 'Verification, Processing' loadi...