Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

iAuthFlow v2 Phishing Toolkit Enrolls Persistent Passkeys That Survive Password Resets

Security researchers detail iAuthFlow v2, a $10k phishing toolkit that captures a Google login, then uses the session to enroll a passkey under the victim’s account—maintaining access even after the user changes their password. For compliance teams, this illustrates the need for robust access‑control monitoring and credential‑management controls in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 24, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

iAuthFlow v2 Phishing Toolkit Enrolls Persistent Passkeys That Survive Password Resets

What Happened — Researchers at Abnormal Security dissected iAuthFlow v2, a $10,000 phishing toolkit sold on a Russian‑language cybercrime forum. The kit captures a victim’s Google login, then uses the authenticated session to enroll a new passkey under the victim’s account—a credential that remains valid even after the user changes their password.

Why It Matters for Compliance & Audit Readiness —

  • SOC 2 access‑control criteria (CC6.1, CC6.2) require continuous monitoring of credential creation and modification; a hidden passkey bypasses typical password‑change checks.
  • Evidence of MFA and passkey lifecycle must be captured and retained to provide a defensible audit trail.
  • Security awareness training must cover credential‑only phishing scenarios, not just password theft.

Who Is Affected — Enterprises that rely on Google Workspace, G‑Suite, or any FIDO2/passkey‑based authentication for employee access across all verticals.

Recommended Actions —

  • Enforce re‑verification for any new passkey enrollment and log the event in a tamper‑evident system.
  • Integrate credential‑creation alerts into your SIEM and map them to SOC 2 CC6.1 evidence.
  • Conduct targeted phishing simulations that include passkey‑enrollment scenarios. Source: SecurityAffairs

Technical Notes — The toolkit performs a browser‑in‑the‑middle attack, relaying the victim’s credentials to a remote browser that logs into Google, then navigates the passkey settings UI to register a new credential. No CVE is involved; the risk stems from social engineering and credential‑management gaps. Source: same article

📰 Original Source
https://securityaffairs.com/197748/cyber-crime/iauthflow-v2-the-10000-phishing-toolkit-that-survives-your-password-reset.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →