< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 4 sources · 4 days · First seen · Last updated

iAuthFlow v2 malware and phishing toolkit

Overview

Security researchers have identified a sophisticated malware toolkit known as iAuthFlow v2, which is being sold on Russian-language cybercrime forums for approximately $10,000. The toolkit targets users of major platforms such as Google, Microsoft, iCloud, and LinkedIn.

Initial reports highlighted that the malware uses phishing campaigns to establish persistent access by registering new login methods or recovery options. This allows attackers to maintain entry even after a victim changes their password.

Subsequent analysis by researchers at Abnormal Security clarified that the toolkit employs a ‘browser-in-the-middle’ attack. This method intercepts credentials, passwords, and two-factor authentication codes by presenting deceptive login pages. The toolkit specifically leverages the authenticated session window to enroll an attacker-controlled passkey into the victim’s account, providing a cryptographic credential that bypasses standard security measures.

Entities

iCloud · Google · iAuthFlow v2 · Microsoft · LinkedIn

Timeline

  1. 1 day ago

    [TECHNOLOGY] 2 sources
    iAuthFlow v2 phishing toolkit enables persistent account access

    The iAuthFlow v2 phishing toolkit, sold for $10,000, allows attackers to enroll their own passkeys into Google accounts, maintaining access even after a victim resets their password.

  2. 6 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity alert: iAuthFlow v2 malware targets major online accounts

    Security researchers warn of iAuthFlow v2, a $10,000 malware kit that uses phishing to gain persistent access to Google, Microsoft, and LinkedIn accounts, making simple password changes insufficient.

Sources

cybernoz.com · launion.net · laverdadnoticias.com · moncloa.com