Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the target completes authentication, Google’s SID and SSID cookies appear in the attacker-controlled browser, which iAuthFlow v2 uses as its signal that the login was successful.
Once that browser has an authenticated Google session, the toolkit can use it to make changes inside the account—including enrolling a new passkey controlled by the operator.
The attack relies on a browser-in-the-middle (BitM) architecture involving two separate browser environments. The target interacts with a Google-styled phishing page in their own browser. Behind that page, iAuthFlow v2 controls a separate browser running on the attacker’s server.
The demonstration shows the operator regaining access to the mailbox without knowing the new password or requiring additional action from the account owner.
Use the Google Workspace Security Investigation Tool to investigate the account, then remove any unauthorized passkeys or security keys, delete malicious Gmail filters and forwarding rules
When an attacker’s access is limited to captured session cookies, those actions normally end that access... But this process does nothing to the new passkey which is a credential registered to the account rather than a token derived from the password.
The attack relies on a browser-in-the-middle (BitM) architecture involving two separate browser environments. The target interacts with a Google-styled phishing page in their own browser. Behind that page, iAuthFlow v2 controls a separate browser running on the attacker’s server.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commercial phishing toolkit/framework that relays victim credentials and authentication flows through an attacker-controlled browser environment, silently registers an attacker-controlled passkey on the victim account, and enables persistent account access even after password resets and session revocation.
A browser-in-the-middle/adversary-in-the-middle phishing toolkit that relays a victim’s Google authentication flow through an attacker-controlled browser, captures an authenticated session, and then uses that session to enroll an attacker-controlled passkey for persistent account access even after password reset and session revocation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.