AI News Feed
Market watch
Cybersecurity

New Malware Toolkit Uses Google Passkeys to Keep Access After Password Reset

A malware toolkit named iAuthFlow v2, sold on Russian forums for $10,000+, lets attackers retain access to email accounts even after password changes and session terminations, according to cybersecurity firm Abnormal.

The malware, named iAuthFlow v2, is being marketed on Russian dark web forums, according to a report from cybersecurity firm Abnormal, which obtained a copy for analysis.

The tool operates as a phishing kit, tricking users into logging into Google, Microsoft, iCloud, or LinkedIn. Once the victim submits their credentials, the malware relays them to the attacker, who logs into the account on their end. The victim sees a temporary "processing" page while, in the background, the tool creates a new passkey linked to an attacker-controlled device.

A passkey is an authentication method that relies on cryptographic keys stored on a device and typically uses a fingerprint, face scan, or device PIN. Because the secret key is never transmitted, passkeys are generally resistant to phishing. But if an attacker generates their own key on their own device, they gain persistent access that does not depend on the victim's password.

The report includes a video demonstration showing iAuthFlow v2 creating a passkey six seconds after a successful authentication. However, Abnormal noted that the process can encounter hiccups; Google, for instance, may require further identity verification before allowing a new passkey to be enrolled.

For most account compromises, changing the password and ending all sessions is sufficient. With iAuthFlow v2, Abnormal recommends that users review their accounts for unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, changes to recovery and delegated access, and unauthorized applications. They should also revoke relevant OAuth tokens and grants, examine sign-in, mail-rule, two-step verification, passkey, and OAuth audit events, and remove any authentication methods enrolled by the attacker.