Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

This new malware can use Google passkeys even after a victim resets their password

A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts

This new malware can use Google passkeys even after a victim resets their password

iAuthFlow v2, a newly discovered malware toolkit, enables cybercriminals to regain access to compromised email accounts even after victims change their passwords. This concerning malware is being sold on Russian dark web forums for over $10,000, according to Abnormal cybersecurity researchers who obtained a copy for analysis.

Primarily functioning as a phishing tool, iAuthFlow v2 targets users attempting to log into Google, Microsoft, iCloud, or LinkedIn. Upon successful login, the attackers intercept the credentials and subsequently log into the accounts themselves. Simultaneously, the tool displays a "processing" page, during which it secretly establishes a new passkey.

Passkeys, touted as the "password killer," offer an alternative authentication method using cryptographic keys stored on a user's device. These keys, accessible via fingerprints, face scans, or device PINs, provide resistance to phishing attempts. However, when threat actors can generate a key on their own device, they can bypass this security measure, ensuring guaranteed access.

The malware's advertisement, which includes a video demonstration, reveals that iAuthFlow v2 generates a passkey six seconds after the initial authentication. While generating a passkey typically involves multiple steps and potential hurdles, such as additional identity verification by Google, the malware streamlines this process. As a result, even after users reset their passwords, the attackers maintain persistent access to the compromised email accounts.

To counteract iAuthFlow v2, security experts recommend thorough account review, including checking for unauthorized passkeys, malicious Gmail filters, forwarding rules, and changes to recovery and delegated access. Users should also revoke suspicious OAuth tokens and grants, investigate sign-in, mail-rule, 2-Step Verification, passkey, and OAuth audit events, and ultimately remove any attacker-enrolled authentication methods from their accounts.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

MG Could Be Next Automaker to Get Apple Car Key Support

Code found in Apple's backend car key system suggests the company is preparing to add support for MG vehicles. The discovery indicates Apple has begun preparing car key support for SAIC Motor's MG brand. With an Apple Car Key, drivers can use their iPhone or Apple Watch to lock, unlock, and start a compatible vehicle instead of relying on…

Nokia 125 4G 2nd Edition is Now Public

HMD appears to be preparing another Nokia-branded feature phone, with the upcoming Nokia 125 4G 2nd Edition surfacing in a … Read More The post Nokia 125 4G 2nd Edition is Now Public appeared first on…

Why Scroll-First Date Pickers Work Better on Mobile

Most date pickers still use the same interaction model they have used for years: Open the calendar. See one month. Click an arrow. See the next month. Repeat until you reach the date you want. That works reasonably well on desktop. On mobile, it often feels strangely outdated.

More from Friday 21 August →