HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Malware‑Driven “Pass the Passkey” Attack Threatens Password‑less Authentication Ecosystems

Unit 42 uncovers malware that can hijack Google’s synced passkey flow, extracting private keys and authenticating without user interaction. The technique highlights gaps in SOC 2 access‑control implementations for password‑less systems.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 unit42.paloaltonetworks.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
unit42.paloaltonetworks.com

Malware‑Driven “Pass the Passkey” Attack Threatens Password‑less Authentication Ecosystems

What Happened – Palo Alto Networks’ Unit 42 research reveals a new class of malware that can hijack Google’s synced passkey flow. By compromising an endpoint, attackers can misuse onboarding, recovery and device‑trust workflows to extract private keys and authenticate without any user interaction.

Why It Matters for Compliance & Audit Readiness

  • The technique directly subverts SOC 2 CC6.1 (Logical Access) and CC6.2 (System Operations) controls that require strong authentication and protection of credential material.
  • Continuous evidence of endpoint hardening, privileged‑access monitoring, and user‑verification policies becomes essential to demonstrate due‑diligence during a SOC 2 audit.
  • Verisq’s SOC 2 Access Controls capability provides the audit‑ready evidence you need to prove that password‑less mechanisms are protected against malware‑driven credential compromise.

Who Is Affected – Cloud‑based SaaS providers, identity‑as‑a‑service platforms, enterprises adopting password‑less login (e.g., Google Workspace, Microsoft Entra), and any organization that relies on passkey authentication for employee or customer access.

Recommended Actions

  • Map the “Pass the Passkey” scenario to SOC 2 CC6.1/CC6.2 controls and verify that endpoint protection, privileged‑access monitoring, and MFA policy enforcement are documented and continuously monitored.
  • Deploy anti‑malware solutions with behavior‑based detection on all devices that can enroll or use passkeys.
  • Enforce strict device‑trust enrollment policies and require periodic re‑authentication for high‑risk accounts.
  • Incorporate the attack flow into security‑awareness training to educate users about the risks of compromised endpoints.

Source: Palo Alto Unit 42 – Pass the Passkey

Technical Notes

  • Attack vector: Malware on a compromised endpoint that accesses the local passkey store and abuses cloud‑based onboarding/recovery APIs.
  • No public CVE; the risk stems from workflow design rather than a software flaw.
  • Data at risk: Private cryptographic keys backing passkeys, enabling full account takeover.

Source: Palo Alto Unit 42 – Pass the Passkey

📰 Original Source
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →