iAuthFlow v2 Phishing Toolkit Enrolls Persistent Passkeys That Survive Password Resets
What Happened — Researchers at Abnormal Security dissected iAuthFlow v2, a $10,000 phishing toolkit sold on a Russian‑language cybercrime forum. The kit captures a victim’s Google login, then uses the authenticated session to enroll a new passkey under the victim’s account—a credential that remains valid even after the user changes their password.
Why It Matters for Compliance & Audit Readiness —
- SOC 2 access‑control criteria (CC6.1, CC6.2) require continuous monitoring of credential creation and modification; a hidden passkey bypasses typical password‑change checks.
- Evidence of MFA and passkey lifecycle must be captured and retained to provide a defensible audit trail.
- Security awareness training must cover credential‑only phishing scenarios, not just password theft.
Who Is Affected — Enterprises that rely on Google Workspace, G‑Suite, or any FIDO2/passkey‑based authentication for employee access across all verticals.
Recommended Actions —
- Enforce re‑verification for any new passkey enrollment and log the event in a tamper‑evident system.
- Integrate credential‑creation alerts into your SIEM and map them to SOC 2 CC6.1 evidence.
- Conduct targeted phishing simulations that include passkey‑enrollment scenarios. Source: SecurityAffairs
Technical Notes — The toolkit performs a browser‑in‑the‑middle attack, relaying the victim’s credentials to a remote browser that logs into Google, then navigates the passkey settings UI to register a new credential. No CVE is involved; the risk stems from social engineering and credential‑management gaps. Source: same article