AI Security AI安全 14h ago Updated 8h ago 更新于 8小时前 41

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets 新型钓鱼工具包利用Passkey在密码重置后保持访问权限

iAuthFlow V2 is a $10,000 phishing-as-a-service toolkit sold on Russian-language cybercrime forums that enables persistent account compromise by silently registering a passkey on the victim's account The attack uses a relay architecture where the attacker operates a second browser environment on their server, relaying credentials and authentication responses between the victim's browser and the target service in real time Unlike traditional phishing that relies on session cookies, iAuthFlow V2 r iAuthFlow V2 是新型钓鱼工具包,支持持久账户访问,可抵抗密码重置 攻击利用双浏览器架构和passkey劫持,绕过传统安全响应机制 工具包售价1万美元,模块另售,基于论坛帖子分析,实际运行未知 传统密码重置和会话撤销措施对此类攻击无效 反映社交工程技术的快速复杂化趋势

58
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • iAuthFlow V2 is a $10,000 phishing-as-a-service toolkit sold on Russian-language cybercrime forums that enables persistent account compromise by silently registering a passkey on the victim's account
  • The attack uses a relay architecture where the attacker operates a second browser environment on their server, relaying credentials and authentication responses between the victim's browser and the target service in real time
  • Unlike traditional phishing that relies on session cookies, iAuthFlow V2 registers a passkey directly to the victim's account, which survives password resets and session revocations, granting the attacker long-term access
  • The analysis is postulated from seller forum posts and demonstrations rather than actual malware acquisition, meaning operational details remain partially unverified
  • Abnormal's key remediation recommendation is that a password reset alone is no longer sufficient to recover a compromised account; passkeys and authorized devices must also be audited and removed

Why It Matters

This represents a significant evolution in phishing methodology, shifting from session hijacking to credential registration hijacking, which undermines a core assumption in incident response: that password resets restore account security. As passkeys become increasingly adopted as a standard authentication mechanism across major platforms like Google, Microsoft, and Apple, threat actors are already weaponizing them, forcing security teams to reconsider their remediation playbooks and defensive strategies.

Technical Details

  • Relay-based phishing architecture: The toolkit operates a two-browser environment — the victim interacts with a phishing page in their own browser, while a second browser on the attacker's server handles the actual authentication with the target service, relaying inputs and responses in real time
  • Passkey registration attack: After initial credential capture, the malware silently registers a ready-made passkey on the victim's account (demonstrated against Gmail), which the attacker controls independently of the password
  • Device fingerprinting: The toolkit immediately applies a device fingerprint to the target's browser and logs every interaction, enabling the attacker to maintain a persistent, context-aware session
  • Persistence mechanism: Because a passkey is a registered credential rather than a derived token, standard password reset and session revocation procedures do not remove it, allowing the attacker to regain access via "try another way" login flows
  • Commercial PhaaS model: The base toolkit is priced at $10,000 with additional modules sold separately, distributed through underground forums such as Exploit, following the growing trend of phishing-as-a-service commercialization

Industry Insight

  • Security teams and incident responders must update their compromise remediation procedures to explicitly include auditing and removing registered passkeys, WebAuthn devices, and trusted authenticators — password resets alone are insufficient against this class of attack
  • As passkey adoption accelerates across consumer and enterprise platforms, authentication providers should consider implementing alerts or mandatory re-authentication flows when a new passkey is registered on an existing account, creating a detectable signal for this attack vector
  • The commercialization and escalating sophistication of PhaaS toolkits like iAuthFlow V2 signal that advanced phishing capabilities are becoming more accessible to a broader range of threat actors, warranting increased investment in behavioral detection, anomaly monitoring, and security awareness training focused on passkey-related social engineering

TL;DR

  • iAuthFlow V2 是新型钓鱼工具包,支持持久账户访问,可抵抗密码重置
  • 攻击利用双浏览器架构和passkey劫持,绕过传统安全响应机制
  • 工具包售价1万美元,模块另售,基于论坛帖子分析,实际运行未知
  • 传统密码重置和会话撤销措施对此类攻击无效
  • 反映社交工程技术的快速复杂化趋势

为什么值得看

对AI从业者而言,此案例展示了AI驱动钓鱼技术的演进,提示需更新安全模型以应对passkey劫持等新型攻击;对行业而言,凸显了身份认证基础设施的脆弱性,推动安全标准升级。

技术解析

  • 双浏览器中继架构:受害者浏览器与攻击者服务器远程浏览器实时同步,凭证和认证响应被中继
  • Passkey静默注入:恶意软件自动为目标浏览器添加预制passkey,诱骗受害者认证攻击者控制的凭证
  • 设备指纹与日志记录:立即应用设备指纹并记录所有用户输入,增强隐蔽性
  • 绕过标准响应:密码重置和会话撤销无法撤销已注册的passkey,攻击者可通过passkey重新登录
  • 分析局限性:基于卖家论坛帖子推断,未实际运行恶意软件,细节可能存在偏差

行业启示

  • 安全响应策略需升级:密码重置已不足够,应强制检查并移除未识别的passkey和设备
  • 身份认证范式转变:passkey等无密码认证虽提升用户体验,但需防范被攻击者利用作为持久访问后门
  • 威胁情报共享紧迫性:此类商业化工具包的扩散要求行业加强协作,及时更新检测规则和防御指南

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究