This new malware can use Google passkeys even after a victim resets their password
A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts
iAuthFlow v2, a newly discovered malware toolkit, enables cybercriminals to regain access to compromised email accounts even after victims change their passwords. This concerning malware is being sold on Russian dark web forums for over $10,000, according to Abnormal cybersecurity researchers who obtained a copy for analysis.
Primarily functioning as a phishing tool, iAuthFlow v2 targets users attempting to log into Google, Microsoft, iCloud, or LinkedIn. Upon successful login, the attackers intercept the credentials and subsequently log into the accounts themselves. Simultaneously, the tool displays a "processing" page, during which it secretly establishes a new passkey.
Passkeys, touted as the "password killer," offer an alternative authentication method using cryptographic keys stored on a user's device. These keys, accessible via fingerprints, face scans, or device PINs, provide resistance to phishing attempts. However, when threat actors can generate a key on their own device, they can bypass this security measure, ensuring guaranteed access.
The malware's advertisement, which includes a video demonstration, reveals that iAuthFlow v2 generates a passkey six seconds after the initial authentication. While generating a passkey typically involves multiple steps and potential hurdles, such as additional identity verification by Google, the malware streamlines this process. As a result, even after users reset their passwords, the attackers maintain persistent access to the compromised email accounts.
To counteract iAuthFlow v2, security experts recommend thorough account review, including checking for unauthorized passkeys, malicious Gmail filters, forwarding rules, and changes to recovery and delegated access. Users should also revoke suspicious OAuth tokens and grants, investigate sign-in, mail-rule, 2-Step Verification, passkey, and OAuth audit events, and ultimately remove any attacker-enrolled authentication methods from their accounts.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.