Urgent.News

What's breaking now, across thousands of outlets.

Tech

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

A Russian-language cybercrime forum offers a phishing kit for $10,000 that can install counterfeit passkeys on hijacked accounts, ensuring uninterrupted access even after passwords are changed. The iAuthFlow v2 package offers extra modules for sale separately. Attackers often get locked out after the victim notices the breach, but passkeys provide a persistent threat.

Abnormal Security evaluated the kit's documentation and demo videos. It utilizes a browser-in-the-middle (BitM) technique with two browser sessions: one for the victim and another for the attacker. The victim thinks they're logging in on their device, while the attacker's browser relays the interaction through the BitM session. The kit shows a waiting screen while it enrolls an attacker-controlled passkey on Google.

This passkey remains effective even after the victim changes their password. The kit's behavior includes opening Google passkey settings through the authenticated browser and requesting a new credential. It's unclear where the private key is stored, but it may use a Chromium-based virtual authenticator without storing the private key on the victim's device.

To investigate an account compromise, defenders should check for new passkeys and other post-compromise changes like rogue passkeys, OAuth grants, recovery methods, Gmail filters, and forwarding rules. Password resets and session revocation are insufficient; organizations must also analyze what changed after authentication, including newly enrolled credentials, recovery methods, OAuth grants, and mailbox settings.

Attackers can still exploit fallback login methods, active sessions, account recovery processes, and other weaknesses. Passkeys, while touted as the future of account security, are not foolproof; attackers can target fallback login methods, active sessions, account recovery processes, and other vulnerabilities. Malware can steal session cookies, and device code phishing is another risk, depending on the organization's OAuth device flow policies.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Content Credentials: Cryptographic Provenance for Images and Video

The Coalition for Content Provenance and Authenticity (C2PA) publishes a standard for attaching a signed history to an image, video, or audio file: what device or tool produced it, what edits were…

  • C2PA develops standard for signed media file history
  • Content Credentials manifest records provenance and edits
  • Absence of manifest doesn't confirm media's authenticity

We Shortened Every Path in Our Unreal Build. That Wasn’t the Real Fix.

This is a submission for DEV's Summer Bug Smash: Smash Stories , powered by Sentry . We had already done the obvious thing. The Unreal Engine 5 project was copied to a very short build root.

  • Developers shortened Unreal build path, causing filename too long error
  • Windows lacks default long path support, requiring registry fix
  • Short paths are useful, but OS config essential for long asset paths

More from Friday 21 August →