started · updated
iAuthFlow v2 phishing toolkit enables persistent account access
Researchers at Abnormal Security have identified a new phishing toolkit named iAuthFlow v2, which is being sold on Russian-language cybercrime forums for a base price of $10,000. The toolkit utilizes a ‘browser-in-the-middle’ attack to intercept credentials, including emails, passwords, and two-factor authentication codes, by presenting victims with a deceptive Google login page.
The primary danger of iAuthFlow v2 lies in its ability to maintain persistent access to a compromised account. Once the initial phishing attack succeeds and the attacker captures the authenticated session, the toolkit uses that window to enroll an attacker-controlled passkey into the victim's account. Because this cryptographic credential is registered to the account, it allows the attacker to bypass security measures and regain access even if the victim changes their password, which would typically invalidate active sessions.