iAuthFlow V2 Phishing Kit Enables Rogue Passkey Enrollment for Persistent Account Access

iAuthFlow V2 Phishing Kit Enables Rogue Passkey Enrollment for Persistent Account Access

First seen 21 Aug 2026, 15:18 UTC Theregisterabnormal.ai 78% similarity 69.5

Article Content

Browse articles
ThreatCluster

The iAuthFlow V2 phishing toolkit, available for $10,000, allows attackers to enroll rogue passkeys on compromised accounts, ensuring persistent access even after victims change their passwords. This attack employs a browser-in-the-middle (BitM) technique, where victims interact with a phishing page while their credentials are relayed to an attacker-controlled browser. The kit targets services like Google, Microsoft, and iCloud, and has been observed in Russian-language cybercrime forums. Abnormal Security has documented the toolkit's capabilities, including a demonstration where a passkey was registered just six seconds after authentication. Organizations should be vigilant for newly registered passkeys during account compromise investigations. The toolkit's architecture enables attackers to bypass traditional security measures like session revocation and password changes.

Key Points: • iAuthFlow V2 phishing kit allows persistent access via rogue passkeys. • The toolkit employs a browser-in-the-middle attack method. • Organizations should monitor for newly registered passkeys post-compromise.

ThreatCluster AI How this analysis works

Timeline

2026-08-21
iAuthFlow V2 toolkit identified
Abnormal Security reported on the iAuthFlow V2 phishing kit, detailing its capabilities and attack method.
abnormal.ai
2026-08-21
iAuthFlow V2 kit advertised on cybercrime forums
The phishing kit was found for sale on Russian-language forums, priced at $10,000 for the base package.
Theregister
2026-08-21
Demonstration of passkey enrollment
A demonstration showed the toolkit enrolling a passkey just six seconds after user authentication.
Theregister

Community

Browse all →

Tracked Entities in This Story