Ethical Hacking News
The iAuthFlow v2 phishing toolkit is a sophisticated attack that can evade traditional password reset methods, allowing attackers to persist even after a password reset. This toolkit uses a browser-in-the-middle attack to steal user credentials and enroll an attacker-controlled passkey that can be used to regain access to the victim's account. To protect against these attacks, organizations should consider using WebAuthn-based authentication and enforcing strict security measures, including the use of security keys and the Advanced Protection Program.
The iAuthFlow v2 phishing toolkit is a sophisticated toolkit that can be purchased on a Russian-language cybercrime forum for $10,000. The toolkit uses a browser-in-the-middle attack to steal user credentials, including email, password, and two-factor code. The toolkit enrolls an attacker-controlled passkey that persists even after a password reset. The passkey module can navigate Google passkey settings and request a new credential, even with identity re-verification. The toolkit targets Google, Microsoft, iCloud, and LinkedIn, with similar post-authentication persistence logic. WebAuthn-based authentication can prevent these attacks, and Google Workspace can enforce this with the "Only security key" option. Security teams should also check the account's passkeys and security keys before closing a compromised account case.
The recent discovery of the iAuthFlow v2 phishing toolkit has sent shockwaves through the cybersecurity community. This sophisticated toolkit, which can be purchased on a Russian-language cybercrime forum for $10,000, has been designed to survive even the most effective password reset methods. The toolkit's creators have outdone themselves with this latest iteration, which not only steals user credentials but also enrolls an attacker-controlled passkey that persists even after a password reset.
According to an analysis published by Abnormal Security, the iAuthFlow v2 toolkit uses a browser-in-the-middle attack, where the victim sees a fake login page that appears to be legitimate, while the attacker's browser runs a remote browser on the attacker's server. This allows the attacker to capture the user's credentials, including their email, password, and two-factor code, which are then sent to the attacker's remote browser for login. The toolkit then uses this authenticated session to enroll a passkey controlled by the operator, which can be used to gain persistent access to the victim's account.
The passkey module navigates the victim's Google passkey settings through the authenticated browser and requests a new credential. Google may ask for identity re-verification before allowing the enrollment; the demo shows the toolkit handling this. The enrolled passkey is then stored on the attacker's side, and the toolkit records "Passkey created and saved." This means that even after a password reset, the attacker can still use the enrolled passkey to regain access to the victim's account.
The iAuthFlow v2 toolkit is not limited to Google; it also targets Microsoft, iCloud, and LinkedIn. The same post-authentication persistence logic applies wherever passkeys can be enrolled. This means that organizations running Google Workspace can use the Security Investigation Tool to audit their accounts before declaring them clean.
The best way to prevent these attacks is to rely on authentication methods that cannot be easily stolen through phishing. WebAuthn-based authentication is tied to the real website, so stolen passwords or codes cannot be used through a relay attack. Google Workspace can enforce this with the "Only security key" option for 2-Step Verification and through the Advanced Protection Program.
The toolkit's price and professional sales channels suggest that this is an ongoing business, not a one-time release. If a Google account is compromised but appears clean after a password reset, security teams should also check the account's passkeys and security keys before closing the case.
In conclusion, the iAuthFlow v2 phishing toolkit represents a significant evolution in phishing tactics. It shows that once an attacker gains legitimate access to an account, that access can become a starting point for establishing new authentication methods, modifying account settings, and creating other forms of persistence. Organizations must take a more comprehensive approach to security, examining not only what changed after authentication but also the newly enrolled credentials, recovery methods, OAuth grants, and mailbox settings.
Related Information:
https://www.ethicalhackingnews.com/articles/iAuthFlow-v2-The-Sophisticated-Phishing-Toolkit-That-Evades-Traditional-Password-Reset-Methods-ehn.shtml
https://securityaffairs.com/197748/cyber-crime/iauthflow-v2-the-10000-phishing-toolkit-that-survives-your-password-reset.html
https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys
Published: Mon Aug 24 05:15:08 2026 by llama3.2 3B Q4_K_M