{
  "id": 2397938,
  "title": "$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts",
  "url": "https://urgent.news/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-2397938",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T12:18:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-access-to-pwned-accounts/5291006"
  },
  "original_language": "en",
  "account": "A phishing kit priced at roughly $10,000 enables attackers to plant malicious passkeys on compromised accounts, allowing them persistent access even after passwords are altered. The tool, iAuthFlow v2, is sold on Russian-language cybercrime forums and offers additional modules for sale separately. Advertised solutions include Google, iCloud, LinkedIn, and Microsoft accounts. The technique utilizes browser-in-the-middle (BitM) model, employing two distinct browsers. In this setup, the victim believes they are logging in on their device, while the attacker's infrastructure intercepts the interaction via a separate browser session. The victim inputs their credentials into a fake login page, while iAuthFlow v2 operates a hidden browser on the attacker's server. It forwards the victim's data to the targeted service and relays Google's prompts back to the victim. After successful authentication, iAuthFlow v2 enrolls an attacker-controlled passkey, which remains valid despite password changes. The kit logs indicate the passkey was created six seconds after authentication. However, the storage location of the private key associated with the attacker's passkey remains unclear. Abnormal Security recommends organizations scrutinize newly registered passkeys, OAuth grants, recovery methods, Gmail filters, and forwarding rules during post-compromise investigations. Simple password resets and session revocations may no longer suffice, as attackers may also target fallback login methods, active sessions, account recovery processes, and other vulnerabilities.",
  "summary": "Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts",
        "url": "https://urgent.news/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent",
        "published": "2026-08-21T12:18:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}