started · updated
Cybersecurity alert: iAuthFlow v2 malware targets major online accounts
Security researchers have identified a sophisticated malware tool known as iAuthFlow v2, which is being sold on Russian underground forums for over $10,000. The tool uses phishing campaigns to target users of major platforms including Google, Microsoft, iCloud, and LinkedIn.
Unlike standard credential theft, this malware aims to establish persistent access by registering new login methods or recovery options within the victim's account. This means that simply changing a password may not be sufficient to regain full security, as the attacker may retain a secondary way to enter the account until the unauthorized access method is manually identified and removed.
To protect accounts, experts recommend using official recovery channels, utilizing trusted devices and connections, and implementing long, unique passwords. Users should also monitor their linked email accounts for unauthorized notifications regarding changes to passwords, phone numbers, or security settings.
Entities
Google · LinkedIn · Microsoft · iAuthFlow v2 · iCloud