This new malware can use Google passkeys even after a victim resets their password
Date:
Fri, 21 Aug 2026 15:05:00 +0000
Description:
A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts Tool phishes logins, then secretly creates attackercontrolled passkeys for lasting access Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods Security researchers have discovered a new malware toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.
iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new report from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis. The malware primarily works as
a phishing tool, trying to trick users into logging into either Google , Microsoft , iCloud , or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end,
as well - before the tool displays a processing page for a few seconds while, in the background, it sets up a new passkey. Latest Videos From TechRadar Watch full video here: How to defend against iAuthFlow v2 A passkey is an alternative means of authentication that is often touted as the password killer. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN.
Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. You may like Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and
gain access to all your secrets Microsoft login pages are being abused as hackers try and lure in unlucky victims Microsoft 365 users hit by phishing scheme posing as RingCentral emails
The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication.
However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro
newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Usually, when a threat actor compromises an email account , terminating all sessions and changing the password is usually enough.
In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.
They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/this-new-malware-can-use-google-passkey s-even-after-a-victim-resets-their-password
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)