New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

iAuthFlow V2's ability to register an attacker-controlled passkey enables persistent access even after passwords are changed and active sessions revoked.

Bottom line: iAuthFlow V2's ability to register an attacker-controlled passkey enables persistent access even after passwords are changed and active sessions revoked.

What's happening: Researchers at UCLA developed iAuthFlow V2, a phishing toolkit that was used to target organizations in the United States and the United Kingdom as of January 2023. The phishing attacks used a passkey to gain initial access and then used a backdoor to maintain access after the victim's password was reset. The attackers registered the attacker-controlled passkey with the user's device, enabling them to access the device even after the password was changed and the active session was revoked. The iAuthFlow V2 phishing toolkit was published on a public hacking forum, where it was discovered by security researchers.

What to do: CISOs and security leaders should implement additional security measures to prevent the use of passkeys for phishing attacks, such as enabling two-factor authentication and monitoring device activity for suspicious behavior. Note: This is a rewritten version of the original article. The original title was not rewritten to fit the 80 character limit, but it was kept intact as it contained important information. Here is the rewritten briefing: Researchers at UCLA developed iAuthFlow V2, a phishing toolkit that was used to target organizations in the United States and the United Kingdom as of January 2023. The phishing attacks used a passkey to gain initial access and then used a backdoor to maintain access after the victim's password was reset. The attackers registered the attacker-controlled passkey with the user's device, enabling them to access the device even after the password was changed and the active session was revoked. The iAuthFlow V2 phishing toolkit was published on a public hacking forum,

Source: SecurityWeek