Urgent.News

What's breaking now, across thousands of outlets.

Tech

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

A phishing kit priced at roughly $10,000 enables attackers to plant malicious passkeys on compromised accounts, allowing them persistent access even after passwords are altered. The tool, iAuthFlow v2, is sold on Russian-language cybercrime forums and offers additional modules for sale separately. Advertised solutions include Google, iCloud, LinkedIn, and Microsoft accounts.

The technique utilizes browser-in-the-middle (BitM) model, employing two distinct browsers. In this setup, the victim believes they are logging in on their device, while the attacker's infrastructure intercepts the interaction via a separate browser session. The victim inputs their credentials into a fake login page, while iAuthFlow v2 operates a hidden browser on the attacker's server.

It forwards the victim's data to the targeted service and relays Google's prompts back to the victim. After successful authentication, iAuthFlow v2 enrolls an attacker-controlled passkey, which remains valid despite password changes. The kit logs indicate the passkey was created six seconds after authentication. However, the storage location of the private key associated with the attacker's passkey remains unclear.

Abnormal Security recommends organizations scrutinize newly registered passkeys, OAuth grants, recovery methods, Gmail filters, and forwarding rules during post-compromise investigations. Simple password resets and session revocations may no longer suffice, as attackers may also target fallback login methods, active sessions, account recovery processes, and other vulnerabilities.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Content Credentials: Cryptographic Provenance for Images and Video

The Coalition for Content Provenance and Authenticity (C2PA) publishes a standard for attaching a signed history to an image, video, or audio file: what device or tool produced it, what edits were…

  • C2PA develops standard for signed media file history
  • Content Credentials manifest records provenance and edits
  • Absence of manifest doesn't confirm media's authenticity

We Shortened Every Path in Our Unreal Build. That Wasn’t the Real Fix.

This is a submission for DEV's Summer Bug Smash: Smash Stories , powered by Sentry . We had already done the obvious thing. The Unreal Engine 5 project was copied to a very short build root.

  • Developers shortened Unreal build path, causing filename too long error
  • Windows lacks default long path support, requiring registry fix
  • Short paths are useful, but OS config essential for long asset paths

More from Friday 21 August →