iAuthFlow v2 malware adds attacker passkeys to hijacked email accounts
This digest was compiled by AI from multiple sources — links to the originals are below.

Security researchers at Abnormal discovered iAuthFlow v2, a malware toolkit sold on Russian forums for over $10,000 that lets attackers regain access to compromised email accounts even after password resets. The tool phishes credentials from Google, Microsoft, iCloud, or LinkedIn, then silently creates an attacker-controlled passkey. Abnormal advises users to audit passkeys, OAuth tokens, mail rules, and remove rogue authentication methods.
Key Facts
- iAuthFlow v2 is sold on Russian dark web forums for over $10,000.
- The malware targets Google, Microsoft, iCloud, and LinkedIn login pages.
- After phishing credentials, iAuthFlow v2 creates an attacker-controlled passkey in about six seconds.
- Abnormal recommends reviewing unauthorized passkeys, OAuth tokens, mail rules, and recovery settings.
Malware Operation
iAuthFlow v2 is sold on Russian dark web forums for over $10,000, according to Abnormal. The toolkit phishes login credentials from Google, Microsoft, iCloud, and LinkedIn. After the victim enters credentials, the tool displays a processing page while it creates a new passkey in the background. A demo video shows the passkey being created six seconds after authentication.
Defense Measures
Abnormal advises users to review accounts for unauthorized passkeys, security keys, Gmail filters, and forwarding rules. Users should revoke relevant OAuth tokens and grants. Organizations should investigate sign-in, mail-rule, 2-Step Verification, passkey, and OAuth audit events. Any attacker-enrolled authentication methods must be removed.
1 source
iAuthFlow v2 malware adds attacker passkeys to hijacked email accounts



