{
  "id": 2394847,
  "title": "This new malware can use Google passkeys even after a victim resets their password",
  "url": "https://urgent.news/2026/08/21/this-new-malware-can-use-google-passkeys-even-after-a-victim-resets",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T15:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/this-new-malware-can-use-google-passkeys-even-after-a-victim-resets-their-password"
  },
  "original_language": "en",
  "account": "iAuthFlow v2, a newly discovered malware toolkit, enables cybercriminals to regain access to compromised email accounts even after victims change their passwords. This concerning malware is being sold on Russian dark web forums for over $10,000, according to Abnormal cybersecurity researchers who obtained a copy for analysis.\n\nPrimarily functioning as a phishing tool, iAuthFlow v2 targets users attempting to log into Google, Microsoft, iCloud, or LinkedIn. Upon successful login, the attackers intercept the credentials and subsequently log into the accounts themselves. Simultaneously, the tool displays a \"processing\" page, during which it secretly establishes a new passkey.\n\nPasskeys, touted as the \"password killer,\" offer an alternative authentication method using cryptographic keys stored on a user's device. These keys, accessible via fingerprints, face scans, or device PINs, provide resistance to phishing attempts. However, when threat actors can generate a key on their own device, they can bypass this security measure, ensuring guaranteed access.\n\nThe malware's advertisement, which includes a video demonstration, reveals that iAuthFlow v2 generates a passkey six seconds after the initial authentication. While generating a passkey typically involves multiple steps and potential hurdles, such as additional identity verification by Google, the malware streamlines this process. As a result, even after users reset their passwords, the attackers maintain persistent access to the compromised email accounts.\n\nTo counteract iAuthFlow v2, security experts recommend thorough account review, including checking for unauthorized passkeys, malicious Gmail filters, forwarding rules, and changes to recovery and delegated access. Users should also revoke suspicious OAuth tokens and grants, investigate sign-in, mail-rule, 2-Step Verification, passkey, and OAuth audit events, and ultimately remove any attacker-enrolled authentication methods from their accounts.",
  "summary": "A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts",
  "key_points": [
    "iAuthFlow v2 malware enables access to compromised email accounts post-password reset.",
    "Malware generates passkeys secretly during login process, bypassing security measures."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}