All incidents

iAuthFlow v2 phishing toolkit bypasses password resets using passkeys

malwareopenAug 21, 2026 — Aug 24, 2026
iAuthFlow v2 phishing toolkit bypasses password resets using passkeys

ABNORMAL Security researchers have uncovered a new phishing toolkit called iAuthFlow v2 that allows attackers to maintain access to victims’ accounts even after a password reset, by registering a permanent passkey during a browser‑in‑the‑middle attack. The toolkit is being sold for $10,000 on a Russian‑language cybercrime forum and targets Google, Microsoft and iCloud services. Details of the campaign were first observed between 21 August and 24 August 2026.

The attack begins when a victim is lured to a counterfeit login page that mimics the legitimate service. While the victim enters their credentials, the attacker’s server maintains a parallel session and completes the WebAuthn registration process, creating a passkey tied to the attacker‑controlled device. Because passkeys are not invalidated by a password change, the attacker can reuse them to regain entry at any time.

iAuthFlow v2 does not rely on a known vulnerability, so no CVE identifiers have been assigned. Instead it abuses the standard WebAuthn flow, exploiting the trust users place in familiar login screens. The toolkit’s ability to inject a passkey without triggering typical security alerts makes it particularly stealthy, and it has been observed harvesting credentials from multiple platforms in a single campaign.

Although no specific threat actor has been attributed to the toolkit, its appearance in a commercial forum indicates that the technique is being offered as a service to various criminal groups. The activity window captured by Abnormal Security shows active use in the wild, underscoring the need for organisations to look beyond password resets when responding to suspected compromises.

Defenders should audit registered passkeys and security keys for any entries that do not correspond to authorised devices. Any unfamiliar WebAuthn credential should be removed immediately, and affected accounts should be subjected to a full session revocation. Enforcing phishing‑resistant multi‑factor authentication and monitoring for atypical authentication attempts can help prevent the initial credential theft.

In addition, security teams must update incident response playbooks to include checks for persistent authentication mechanisms after a password reset. User training should emphasise the importance of verifying the legitimacy of login pages, even when the URL appears correct. By treating passkeys as another potential foothold, organisations can close the gap that iAuthFlow v2 attempts to exploit.

Intelligence briefing updated Aug 24, 2026

Root sourceabnormal.ai
Timeline Coverage

Swipe to explore timeline