securityaffairs.com 8/24/2026, 8:21:17 AM · external

iAuthFlow v2 bypasses password resets with permanent passkeys

iAuthFlow v2 bypasses password resets with permanent passkeys
Developing story malware 2 articles tracked
iAuthFlow v2 phishing toolkit bypasses password resets using passkeys
CyberSIXT Evidence Panel
Primary Source abnormal.ai

IAUTHFLOW v2 is a sophisticated phishing toolkit analyzed by Abnormal Security researchers, sold for $10,000 in a Russian-language cybercrime forum. It exploits a phished Google login to create a permanent passkey that survives password resets, allowing attackers to regain access even after victims change passwords. The toolkit employs a browser-in-the-middle attack, making it appear as a legitimate Google login while capturing victim credentials.

The report highlights the importance of thorough incident response beyond mere password resets, emphasizing the need to check for unauthorized authentication methods and passkeys. The toolkit targets multiple platforms like Microsoft and iCloud, illustrating a significant evolution in phishing tactics.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline