ELSEIF
Your brief EB
354 stories from 119 feeds 480 clusters Refreshed 10 minutes ago next pull 16:23

SECURITY Signal 438

$10K phishing kit reportedly plants rogue passkeys for persistent access after credential rotation

A phishing kit sold on cybercrime forums for around $10,000 claims to use browser-in-the-middle attacks to enroll attacker-controlled passkeys on compromised accounts, maintaining access even after password changes.

WHY IT MATTERS

Passkeys are designed to resist phishing, but this kit targets the passkey enrollment process itself rather than the authentication step. Incident responders who rely on password resets and session revocation may miss persistent attacker access through rogue passkeys, requiring comprehensive account audits instead.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

iAuthFlow v2 uses a browser-in-the-middle attack to relay victim authentication and then enroll an attacker-controlled passkey within seconds.

02

The kit's claims have not been independently verified, as researchers examined documentation and demos but did not purchase or test it.

03

Incident response must now include auditing for newly enrolled passkeys, OAuth grants, and recovery methods rather than stopping at password resets.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles $10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts Open ↗