تخطي إلى المحتوى الرئيسي
Cyber News SecurityWeek 7 hours ago

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Se
SecurityWeek
Phishing

iAuthFlow V2 is a new phishing toolkit demonstrating the rapidly improving sophistication of phishing techniques.

iAuthFlow V2 is a malware toolkit first seen on a Russian-language cybercrime forum. It is an advanced form of phishing that offers persistent access to the victim’s account, surviving a password reset.

The base toolkit is offered for sale at $10,000, with additional modules available separately. Using available information from the seller’s forum posts and demonstrations (but without acquiring or running the malware), Abnormal researchers have postulated an analysis of its operation, based on the ‘passkey’ module and employed against a Gmail account.

The target is phished in the normal manner, landing on an attacker-controlled web page that is displayed in the target’s browser. The attack requires the phish to be successful, and for the target to be fooled into entering credentials. However, unseen by the target, the attacker has a separate but connected second browser environment on the attacker’s own server.

In the normal course of events, a compromise is detected either rapidly or eventually. Standard procedure for the victim is a password reset, which breaks the attacker’s access. But not if iAuthFlow V2 is the compromise method. As the target interacts with the primary phishing page, the credentials and authentication responses are relayed to the remote browser, which is what actually responds to the target.

The malware immediately applies a device fingerprint to the target’s browser. Each entry from the target is logged. The malware silently adds a ready-made passkey, and all is relayed to the second browser environment. Google, from the second browser but via the initial phishing page, asks the target to authenticate. If the initial phish is successful, the target will do so, but without knowing that this now includes authenticating the attacker-controlled passkey.

Advertisement. Scroll to continue reading.

When the victim discovers the compromise, a password reset and session revocation will normally cut off the attacker’s access – and is the standard response to a phishing compromise. 

Written By Kevin Townsend

View Original Report

This intelligence was aggregated from SecurityWeek.

Read on Source
Advertisement