Researchers say a phishing toolkit called iAuthFlow V2 can keep access to a victim’s account even after the victim changes their password. Abnormal’s analysis, based on underground sales posts and demos, says the kit relays a victim’s Gmail login through an attacker-controlled browser and silently registers an attacker-controlled passkey, a login credential tied to the account rather than the password, allowing later re-entry via the 'try another way' flow.
Why it matters: This raises the stakes for phishing because normal recovery steps like changing a password and revoking sessions may no longer fully remove an attacker. Organizations should review passkey enrollment and recovery flows, audit newly registered authenticators, and warn users to be wary of login pages and prompts that seem routine during sign-in.
Kevin Townsend
2026.08.21
100% relevant
This article establishes a distinct story around iAuthFlow V2 and its passkey-persistence phishing technique rather than updating an already tracked specific campaign or toolkit event.
← Back to all stories