{
  "id": 2395352,
  "title": "$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts",
  "url": "https://urgent.news/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T12:18:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/cyber-crime/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-access-to-pwned-accounts/5291006"
  },
  "original_language": "en",
  "account": "A Russian-language cybercrime forum offers a phishing kit for $10,000 that can install counterfeit passkeys on hijacked accounts, ensuring uninterrupted access even after passwords are changed. The iAuthFlow v2 package offers extra modules for sale separately. Attackers often get locked out after the victim notices the breach, but passkeys provide a persistent threat. Abnormal Security evaluated the kit's documentation and demo videos. It utilizes a browser-in-the-middle (BitM) technique with two browser sessions: one for the victim and another for the attacker. The victim thinks they're logging in on their device, while the attacker's browser relays the interaction through the BitM session. The kit shows a waiting screen while it enrolls an attacker-controlled passkey on Google. This passkey remains effective even after the victim changes their password. The kit's behavior includes opening Google passkey settings through the authenticated browser and requesting a new credential. It's unclear where the private key is stored, but it may use a Chromium-based virtual authenticator without storing the private key on the victim's device. To investigate an account compromise, defenders should check for new passkeys and other post-compromise changes like rogue passkeys, OAuth grants, recovery methods, Gmail filters, and forwarding rules. Password resets and session revocation are insufficient; organizations must also analyze what changed after authentication, including newly enrolled credentials, recovery methods, OAuth grants, and mailbox settings. Attackers can still exploit fallback login methods, active sessions, account recovery processes, and other weaknesses. Passkeys, while touted as the future of account security, are not foolproof; attackers can target fallback login methods, active sessions, account recovery processes, and other vulnerabilities. Malware can steal session cookies, and device code phishing is another risk, depending on the organization's OAuth device flow policies.",
  "summary": "Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts",
        "url": "https://urgent.news/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-2397938",
        "published": "2026-08-21T12:18:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}