This new malware can use Google passkeys even after a victim resets their password
- iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts
- Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access
- Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods
Security researchers have discovered a new malware toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.
iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new report from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.
The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE