Researchers reported that iAuthFlow V2, a phishing toolkit advertised on a Russian-language cybercrime forum, can hijack a victim’s successful login and silently register an attacker-controlled passkey on the compromised account. The toolkit reportedly uses a browser-in-the-middle relay to capture credentials and authentication responses during a phishable sign-in flow, then authenticates an attacker-controlled browser session to enroll the new passkey. Demonstrations analyzed by Abnormal focused on Google accounts, where victims entered a password and authenticator-app code while the attacker gained a persistent credential tied directly to the account.
The reported persistence means attackers may be able to regain access even after a password reset and session revocation, because the enrolled passkey remains valid unless it is explicitly removed. The seller also advertised modules for Microsoft, iCloud, and LinkedIn, with pricing reportedly starting at $10,000 plus add-ons. Researchers said their findings were based on forum posts, Telegram content, demonstration videos, and vendor documentation rather than direct execution of the toolkit, and warned that incident response for such compromises should include checking for unauthorized passkeys, OAuth grants, and malicious mailbox rules instead of relying solely on password changes.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Abnormal published an analysis describing how iAuthFlow v2 can maintain access to compromised Google accounts by enrolling attacker-controlled passkeys that survive password resets and session revocation. The report said the researchers based their assessment on seller forum posts, Telegram content, demonstration videos, and Google documentation rather than executing the toolkit themselves, and included remediation guidance and indicators of compromise.
In the demonstrated attack analyzed by Abnormal, iAuthFlow v2 relayed a victim's Google credentials and MFA responses through an attacker-controlled browser session, then used the authenticated session to silently enroll an attacker-controlled passkey on the victim's account. The demonstration also showed the operator later regaining access with that passkey after the account owner changed the password and revoked the active session.
Abnormal reported tracking iAuthFlow v2 after it appeared on a Russian-language cybercrime forum, where the seller advertised the phishing toolkit for a base price of $10,000 with additional modules sold separately. The seller also advertised versions targeting Google, Microsoft, iCloud, and LinkedIn.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcereddit.com
Open sourcesecurityweek.com
Open sourceabnormal.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.