A phishing toolkit named iAuthFlow V2, first spotted on a Russian-language cybercrime forum, can register an attacker-controlled passkey during an attack, giving criminals persistent account access even after the victim changes their password and active sessions are revoked.
Passkeys are meant to replace passwords with device-bound cryptographic credentials, but the kit shows the mechanism can be turned against its users. By enrolling the attacker’s passkey on the victim’s account, the tool leaves a backdoor that survives the standard response to a compromised login: password rotation and session termination. Researchers describe the development as evidence of the rapidly improving sophistication of phishing techniques.
The technique matters as passkey adoption spreads across enterprises. Security teams should treat passkey enrollment as a high-risk account action, watch for unexpected credential registration events, and monitor for authentication with newly added passkeys shortly after phishing activity. Defense-in-depth such as device attestation and step-up verification for passkey binding can blunt the attack.
The kit also underscores that credential-reset processes, long considered the safety net after a breach, no longer guarantee recovery when attackers control the recovery mechanism itself.
