New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Summary
Researchers have identified a new phishing toolkit, iAuthFlow V2, that leverages passkeys to maintain persistent access to accounts. This toolkit can register an attacker-controlled passkey, allowing them to retain access even if the user resets their password or revokes active sessions.
IFF Assessment
This new phishing toolkit poses a significant threat to users by enabling attackers to maintain access even after traditional security measures like password resets are employed.
Defender Context
Defenders should be aware of this new phishing technique that bypasses traditional password reset defenses by utilizing passkeys. This highlights the evolving threats in credential stuffing and account takeover, necessitating robust multi-factor authentication implementations and user education on passkey security best practices.