cybersecurity••5 min read

The $10K Phishing Kit That’s Putting Your Passkeys at Risk

A sophisticated new phishing kit dubbed 'iAuthFlow v2' is bypassing traditional security measures by registering attacker-controlled passkeys. This $10,000 tool enables persistent account access that can survive even password resets.

The $10K Phishing Kit That’s Putting Your Passkeys at Risk

A New Threat to Your Digital Identity

Passkeys have long been hailed as the silver bullet for phishing, relying on asymmetric cryptography to replace vulnerable, shared secrets like passwords. However, a dangerous new development has surfaced: a $10,000 phishing kit named iAuthFlow v2 that claims to exploit the very authentication flows meant to keep users safe.

Unlike traditional credential harvesting, this kit employs a 'browser-in-the-middle' (AitM) approach. It intercepts the authentication process in real-time, allowing attackers to register their own rogue passkeys to an account almost immediately after a victim authenticates. This grants the attacker a backdoor that remains active even if the user manages to reset their password.

How the Attack Works

The danger lies in how the kit manipulates the login ceremony. By inserting itself between the user and the legitimate service, the kit can trick the user into a flow where the attacker's device is registered as a trusted authenticator.

  • Interception: The victim interacts with a malicious site that mimics a legitimate service.
  • AitM Execution: The kit captures session data and authentication requests in real-time.
  • Rogue Registration: Seconds after the user authenticates, the attacker’s device registers a new passkey to the account.
  • Persistence: Because the attacker now holds a registered passkey, they maintain access regardless of future password resets.

Passkeys bind cryptographically to the legitimate domain, making phishing impossible. However, the efficacy of this security relies entirely on the integrity of the registration and authentication ceremony.

— Security Research Consensus

Why Traditional Defenses Are Struggling

Security experts have long noted that passkeys are not a total panacea if implementation is flawed. For instance, if an identity provider allows for 'MFA fallbacks'—such as SMS or email codes—attackers can manipulate the flow to bypass the stronger passkey requirement entirely. The iAuthFlow v2 kit highlights that as long as there is a 'weakest link' in the authentication chain, attackers will find a way to exploit it.

To mitigate these risks, IT and security teams are being urged to monitor for suspicious registration events. Alerting on authentication flows where a user has a passkey enrolled but opts for a weaker method can be a significant indicator of an active AitM attack.

Key Takeaways

  • A new $10,000 phishing kit, iAuthFlow v2, uses browser-in-the-middle attacks to register rogue passkeys.
  • The attack allows for persistent account access that survives standard password resets.
  • The technique exploits the authentication ceremony rather than cracking the cryptographic strength of the passkeys themselves.
  • Organizations should monitor for MFA downgrade attempts and unusual registration patterns.
  • Relying on weak fallback methods like SMS or email codes continues to be a primary vulnerability for account security.

FAQ

Can passkeys still be phished?

Passkeys themselves are resistant to traditional phishing because they are cryptographically bound to a specific domain. However, attackers are now targeting the authentication process to register their own devices as 'legitimate' users.

What is a browser-in-the-middle attack?

It is an attack where the adversary intercepts communications between the user and the service, allowing them to view and manipulate authentication traffic in real-time.

How can I protect my accounts?

Be cautious of suspicious links, ensure your service providers do not allow weak MFA fallbacks, and monitor account activity for unexpected new device or passkey registrations.

Why does changing my password not fix this?

If an attacker has successfully registered their own passkey to your account, they have a legitimate, persistent credential. Resetting a password only changes the password; it does not revoke the attacker's registered passkey.

Related Videos

How Adversary-in-the-Middle (AitM) Attacks Steal Session Tokens & Bypass MFA

Huntress

How Hackers Bypass Two-Factor Authentication - Man-in-the-Middle Attacks Explained

Blue Light IT - Cyber Resilience Experts

The Magic Behind the Padlock Icon On Your Browser - TLS

Mrs.Compile

Sources