This new malware can use Google passkeys even after a victim resets their password

this-new-malware-can-use-google-passkeys-even-after-a-victim-resets-their-password
This new malware can use Google passkeys even after a victim resets their password
Gmail app listing
(Image credit: Ascannio / Shutterstock)

  • iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts
  • Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access
  • Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods

Security researchers have discovered a new malware toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.

iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new report from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.

The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well – before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey.

How to defend against iAuthFlow v2

A passkey is an alternative means of authentication that is often touted as the “password killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN.

Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed.

The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication.

However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Usually, when a threat actor compromises an email account, terminating all sessions and changing the password is usually enough.

In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.

They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.


Best antivirus software header

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Leave a Reply

Your email address will not be published. Required fields are marked *