SECURITY Signal 438
$10K phishing kit reportedly plants rogue passkeys for persistent access after credential rotation
A phishing kit sold on cybercrime forums for around $10,000 claims to use browser-in-the-middle attacks to enroll attacker-controlled passkeys on compromised accounts, maintaining access even after password changes.
Passkeys are designed to resist phishing, but this kit targets the passkey enrollment process itself rather than the authentication step. Incident responders who rely on password resets and session revocation may miss persistent attacker access through rogue passkeys, requiring comprehensive account audits instead.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
iAuthFlow v2 uses a browser-in-the-middle attack to relay victim authentication and then enroll an attacker-controlled passkey within seconds.
The kit's claims have not been independently verified, as researchers examined documentation and demos but did not purchase or test it.
Incident response must now include auditing for newly enrolled passkeys, OAuth grants, and recovery methods rather than stopping at password resets.
THE CLUSTER