Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Cybercriminal kit sells $10K tool to hijack accounts via rogue passkeys

A phishing kit advertised on Russian-language forums claims it can enroll attacker-controlled passkeys on compromised accounts, giving persistent access even after passwords are changed.

A phishing toolkit called iAuthFlow v2 is being sold on Russian-language cybercrime markets for roughly $10,000, with extra modules available separately. The kit employs a browser-in-the-middle (BitM) attack, where the victim’s login is forwarded through an attacker-controlled browser session that mimics the target service. Once the victim completes authentication, the tool uses the authenticated session to enroll a passkey that the attacker controls, allowing continued access even after the victim changes passwords.

Demonstrations highlighted Google, while the vendor also advertises versions for iCloud, LinkedIn and Microsoft. Abnormal Security reviewed the kit’s documentation and demo videos, noting the rapid six-second passkey creation, but could not test the product directly, leaving the storage method of the private key uncertain. The researchers advise organizations to look for newly added passkeys and other post-compromise changes during incident response, emphasizing that password resets alone may be insufficient.

Why it matters

Attackers could retain access to accounts even after victims change passwords, undermining current security practices.

In this story

phishing kitpasskey hijackingbrowser-in-the-middleiAuthFlow v2account compromisepersistent accesscybercrime forumsecurity response
Get the beta ↗