iAuthFlow v2 Turns a Simple Phishing Attack Into a Long-Term Account Takeover Threat + Video

Listen to this Post

Featured ImageIntroduction: The Password Reset That May Not Save You

Phishing has always been dangerous because it tricks people into handing over something valuable: a password, a verification code, or an authenticated session. But the latest generation of phishing kits is changing the equation.

Researchers at Abnormal Security have analyzed iAuthFlow v2, a Russian-language cybercrime toolkit reportedly offered for a base price of $10,000, with additional modules sold separately. What makes the toolkit particularly concerning is not merely its ability to capture Google credentials or bypass multi-factor authentication. Its most dangerous capability is what it can do after the attacker gets inside the account.

The toolkit can reportedly use a

That single step fundamentally changes the incident.

A stolen password can be changed. A stolen session can be revoked. A malicious passkey, however, can remain behind as a separate authentication method until someone discovers and removes it.

This creates a disturbing scenario: a victim realizes something is wrong, changes the password, terminates sessions, and believes the account is secure again. Yet the attacker can potentially return through a passkey they secretly registered minutes earlier.

The lesson is uncomfortable but increasingly important: account recovery is no longer simply about changing the password. It is about discovering everything an attacker changed while they had legitimate access.

The Real Innovation Behind iAuthFlow v2

The most important feature of iAuthFlow v2 is not conventional phishing.

It is persistence.

Traditional phishing attacks generally follow a familiar sequence. The attacker creates a convincing login page, the victim enters credentials, and the attacker uses those credentials to access the account.

More advanced phishing kits add a browser-in-the-middle mechanism that allows attackers to capture authentication information and relay it to the legitimate service in real time.

iAuthFlow v2 reportedly takes the next step.

Instead of treating the authenticated session as the final prize, the attacker uses that temporary access to establish a new authentication mechanism.

The temporary foothold becomes the doorway for permanent persistence.

How the Browser-in-the-Middle Attack Works

The toolkit reportedly uses a browser-in-the-middle, or BitM, architecture.

The victim believes they are interacting with a legitimate Google authentication process. Behind the scenes, however, the toolkit operates another browser controlled by the attacker.

Information entered by the victim, including credentials and authentication codes, can be relayed to the attacker’s remote browser.

The attack therefore does not necessarily need to “break” Google’s authentication system.

Instead, it abuses the trust relationship between the victim and the legitimate website.

The victim performs the authentication normally.

The attacker simply positions themselves between the victim and the service.

A Convincing Login Page Can Be Enough

According to the analysis, the demonstration used a trycloudflare.com subdomain.

That detail is significant because HTTPS and a valid TLS certificate can make a malicious website appear more legitimate to an unsuspecting user.

A padlock icon does not prove that a website belongs to Google.

Encryption protects the connection between the browser and the website. It does not guarantee that the website itself is trustworthy.

This distinction remains one of the most misunderstood aspects of modern phishing.

A perfectly encrypted malicious website is still a malicious website.

The Six-Second Window

One of the most striking details in the researchers’ demonstration is the speed of the persistence mechanism.

The session log reportedly showed the victim completing authentication at approximately 21:37:18.

Only seconds later, at approximately 21:37:24, the toolkit recorded that the passkey had been created and saved.

That is roughly a six-second transition from authenticated access to additional authentication persistence.

The significance is not simply the number six.

It demonstrates how quickly an automated phishing platform can transform a temporary compromise into something much more durable.

An attacker does not necessarily need hours inside the mailbox.

They may need only enough time to change the future authentication landscape of the account.

The Victim Is Kept Waiting

The toolkit reportedly holds the victim on a page displaying a status similar to “Verification, Processing.”

From the

Behind that screen, however, the

This is an important psychological component of the attack.

The victim is not necessarily watching an obvious takeover.

They may simply believe Google is processing a login.

Meanwhile, the attacker is potentially performing actions that the victim does not see.

The Attacker Enrolls a New Passkey

Once the attacker has the authenticated session, the passkey component reportedly navigates through Google’s passkey settings.

The goal is straightforward.

Create another authentication credential and place it under the attacker’s control.

The process may involve additional identity verification depending on the account and Google’s security controls. The demonstration reportedly showed the toolkit handling that stage.

After registration, the attacker possesses a credential that can potentially be used during a later authentication attempt.

This is where the attack becomes much more dangerous than ordinary session theft.

Why a Password Reset May Not Be Enough

A password reset is one of the first actions people take after discovering an account compromise.

It makes sense.

If someone knows your password, changing it prevents them from continuing to use that password.

But a passkey is not simply another copy of the password.

It is a separate authentication credential.

Therefore, changing the password does not automatically mean that every authentication method previously added to the account has disappeared.

This creates an uncomfortable recovery problem.

The victim can successfully change the password.

Existing sessions can be terminated.

The attacker can appear to be gone.

Yet an attacker-controlled passkey may remain registered.

The Attacker Comes Back Through “Try Another Way”

The demonstration reportedly showed exactly why this matters.

After the victim changed the password, the original attacker session stopped functioning.

Under normal circumstances, this might look like a successful recovery.

But the attacker could select “Try another way” during a later login and use the previously enrolled passkey.

The attacker therefore obtains another path into the account.

This is the difference between access and persistence.

The phishing attack creates access.

The passkey creates persistence.

Passkeys Are Not the Problem

It is important not to misunderstand what researchers are demonstrating.

The issue is not that passkeys are inherently insecure.

In fact, properly used passkeys and WebAuthn-based authentication are among the strongest defenses against traditional credential phishing.

The problem occurs when an attacker first obtains legitimate authenticated access and then uses that access to register their own authentication credential.

The technology itself is not necessarily being broken.

The attacker is abusing an authorized account-management capability after gaining access.

That distinction is critical.

The Cryptographic Credential Changes the Game

Passwords are knowledge-based credentials.

Passkeys are cryptographic credentials.

A passkey registration creates a credential associated with the account, and the corresponding private key is designed to remain under the control of the authenticator.

That means an attacker who successfully enrolls their own passkey is not simply stealing a temporary secret.

They are potentially adding themselves to the

This is why incident responders must think beyond passwords.

The question after an account compromise should not only be:

Did we change the password?

It should be:

“What authentication methods exist on this account now?”

The Virtual Authenticator Possibility

Abnormal Security also discusses a technically plausible mechanism involving Chromium’s software-based virtual authenticators.

These tools can support WebAuthn registration and retain cryptographic credentials without requiring a physical security key.

However, researchers did not confirm that this specific technology is what iAuthFlow v2 uses internally.

That distinction matters.

The demonstration shows behavior consistent with passkey-based persistence, but the exact implementation used by the commercial toolkit remains uncertain.

Security analysis should separate what has been demonstrated from what is technically plausible.

The Threat Goes Beyond Google

The version examined by researchers reportedly targets Google.

But the seller allegedly advertises versions designed for other major services, including Microsoft, iCloud, and LinkedIn.

That makes the underlying concept more significant than a single Google-focused phishing kit.

If a platform allows authenticated users to enroll additional authentication methods, attackers who obtain sufficient access may attempt to abuse that capability.

The underlying strategy is therefore broader:

Phish the user, obtain authenticated access, create persistence, and return later.

The Cybercrime Economy Is Becoming More Professional

The reported $10,000 starting price is another important part of the story.

This is not the profile of a crude phishing page distributed by an inexperienced criminal.

A high-priced toolkit with separately sold modules suggests a commercial ecosystem in which sophisticated attack capabilities are packaged and sold to other criminals.

That mirrors a broader trend across cybercrime.

Attackers increasingly do not need to develop every capability themselves.

They can rent infrastructure.

Buy phishing kits.

Purchase malware modules.

Acquire access.

Outsource specialized operations.

The result is a professionalized criminal economy where advanced techniques become available to a much larger pool of attackers.

The New Definition of Account Compromise

For years, security teams often thought about account takeover in relatively simple terms.

An attacker steals a password.

The organization resets it.

Sessions are revoked.

The incident is closed.

That model is increasingly outdated.

Modern attackers can modify the account while they are inside.

They can add authentication credentials.

Change recovery information.

Create forwarding rules.

Grant OAuth permissions.

Add delegates.

Modify mailbox filters.

Create app passwords where permitted.

The compromise therefore becomes a configuration integrity problem, not merely a credential problem.

What Organizations Must Check After an Attack

Security teams responding to a suspected iAuthFlow-style compromise should conduct a much broader review.

The first step is still to reset the password where appropriate.

But that should be considered only one component of remediation.

Teams should inspect all registered passkeys and security keys.

They should verify recovery email addresses and phone numbers.

They should inspect Gmail forwarding rules and filters.

They should investigate mailbox delegation.

They should review OAuth applications and granted permissions.

They should inspect app passwords where applicable.

They should review recent authentication activity.

They should investigate suspicious administrative changes.

And they should determine what happened during the attacker’s authenticated window.

Google Workspace Investigation Matters

Organizations using Google Workspace have additional visibility through security and investigation capabilities.

Security teams should examine the compromised account before declaring the incident resolved.

The goal is not simply to prove that the attacker can no longer use the old session.

The goal is to prove that the attacker has not left behind another route back into the account.

That distinction can determine whether an incident is truly contained.

Strong Authentication Can Stop the Initial Phishing Stage

The strongest defense remains preventing the attacker from obtaining the authenticated session in the first place.

WebAuthn-based authentication is particularly valuable because credentials are cryptographically associated with the legitimate website origin.

A password and one-time verification code can potentially be relayed.

A properly implemented WebAuthn authentication process is substantially harder to proxy through a conventional phishing page.

This is why phishing-resistant authentication should be treated as a strategic security control rather than simply another checkbox in an MFA policy.

Deep Analysis: Understanding the Attack and Defensive Commands

Start With Authentication Logs

During an investigation, security teams should first establish when the suspicious authentication occurred.

For Linux-based log analysis, a basic search might begin with:

grep -Ei "login|authentication|session|oauth|webauthn|passkey" /var/log/auth.log

The exact log sources vary considerably between Linux distributions and cloud services, so this command should be treated as a starting point rather than a universal forensic procedure.

Search for Suspicious Authentication Changes

Security teams can also search collected logs for authentication-related configuration changes:

grep -Ei "credential|security key|passkey|webauthn|recovery|mfa|2fa" security.log

The objective is to identify changes that occurred shortly after the suspicious login.

Timing is extremely important.

A newly registered authentication method six seconds after a suspicious login is far more suspicious than an unrelated credential change months earlier.

Inspect OAuth Activity

OAuth persistence is another major concern.

A defensive investigation can search exported logs for suspicious OAuth activity:

grep -Ei "oauth|authorization|grant|consent|token" security.log

Security teams should then correlate the events with the affected account and determine whether the authorization was expected.

Search Mailbox Rules

For environments where mailbox configuration is available through administrative APIs or exported audit data, investigators should look for forwarding and filtering activity.

A generic log search could include:

grep -Ei "forward|forwarding|filter|rule|delegate" mail-audit.log

Attackers frequently use mailbox rules to maintain visibility into future communications even after other access has been removed.

Check for Persistence Before Closing the Incident

A useful incident-response principle is:

Compromise detected

Reset credentials

Revoke sessions

Inspect passkeys/security keys

Review OAuth permissions

Review recovery settings

Review mailbox rules

Review delegates

Review authentication logs

Confirm no persistence remains

The critical addition is the inspection stage after session revocation.

Without it, the organization may remove the

Use Timeline Correlation

One of the most effective investigative techniques is timeline correlation.

If suspicious authentication occurs at:

21:37:18

and a new passkey appears at:

21:37:24

the six-second relationship deserves immediate investigation.

Security teams should correlate:

Login

→ MFA event

→ Session creation

→ Credential enrollment

→ Account-setting changes

→ OAuth changes

→ Mailbox modifications

The sequence often reveals the

Never Trust a Clean Password Reset

A successful password reset is evidence of remediation.

It is not evidence that the account is clean.

That distinction should become standard incident-response thinking.

If the attacker had administrator-like control over account settings for even a short period, every security-sensitive setting should be treated as potentially modified until verified.

What Undercode Say: Why iAuthFlow v2 Is More Dangerous Than Ordinary Phishing

1. Phishing Has Entered the Persistence Era

The most important development here is the shift from credential theft to persistence engineering.

Attackers are no longer satisfied with stealing something the victim can easily replace.

They want to leave behind something that survives the recovery process.

  1. The Six-Second Demonstration Is the Real Warning

Six seconds sounds insignificant.

From a security perspective, it is enormous.

It demonstrates that automation can turn a short authentication window into a long-term foothold almost immediately.

3. Password Resets Are Becoming Incomplete

Organizations have trained employees to think that changing a password solves an account compromise.

That advice is no longer sufficient.

Modern incident response needs to include authentication-method auditing.

4. Passkeys Can Become an

Passkeys are excellent defenses when users authenticate with them directly.

But any security technology can become dangerous when an attacker gains legitimate administrative control over the account.

The problem is not the passkey itself.

The problem is unauthorized enrollment.

5. Identity Has Become the New Perimeter

Traditional cybersecurity focused heavily on networks and endpoints.

Cloud accounts have changed that equation.

A compromised identity can give an attacker access to email, files, applications, internal communications, cloud infrastructure and business systems.

Identity security therefore deserves the same attention historically given to firewalls and endpoint protection.

  1. The Attacker Does Not Need to Break Google

This is perhaps the most important conceptual point.

The attack does not necessarily require bypassing

The attacker abuses the

That makes these attacks particularly challenging because legitimate operations can be weaponized.

7. Browser-in-the-Middle Attacks Are Getting More Mature

Browser-in-the-middle attacks have evolved considerably.

The attacker can increasingly create a seamless experience where the victim believes they are completing a normal authentication process.

The technology behind the attack is becoming less visible to the victim.

8. The Victim May See Nothing Suspicious

A convincing loading screen can hide the most important stage of the attack.

The victim might close the browser believing authentication simply took too long.

Meanwhile, the attacker has already completed the objective.

9. Cybercrime Is Becoming Modular

The $10,000 base price and additional modules illustrate a larger trend.

Attack infrastructure is increasingly modular.

One criminal group can specialize in phishing.

Another can provide infrastructure.

Another can provide persistence.

Another can monetize stolen accounts.

That specialization makes the overall ecosystem more resilient.

10. Security Teams Must Investigate What Changed?

This should become one of the most important questions in identity incident response.

What changed after the attacker authenticated?

That question can expose passkeys, recovery changes, OAuth grants, forwarding rules and other persistence mechanisms.

  1. Authentication Logs Are More Valuable Than Ever

Authentication logs are no longer simply useful for identifying who logged in.

They can reveal the sequence of events surrounding an attack.

The relationship between login and configuration change can expose automated persistence.

12. Time Correlation Can Reveal Automation

Human attackers do not always move at machine speed.

Automated tooling does.

A suspicious login followed seconds later by a credential enrollment should therefore receive immediate attention.

13. Organizations Need Better Identity Telemetry

Many companies have excellent endpoint monitoring but comparatively weak visibility into cloud identity configuration.

That imbalance is dangerous.

Attackers are increasingly targeting the identity layer because it provides access without necessarily requiring malware.

14. Recovery Must Become Multi-Layered

Incident recovery should include:

Password reset.

Session revocation.

Passkey review.

Security-key review.

OAuth review.

Recovery-setting review.

Mailbox-rule review.

Delegation review.

This is the new minimum for sophisticated account takeover investigations.

15. Phishing-Resistant MFA Is the Strategic Answer

The best defense is preventing the attacker from obtaining a usable authenticated session.

Phishing-resistant authentication significantly raises the difficulty of browser-relay attacks.

Organizations should prioritize it wherever operationally possible.

16. Security Awareness Still Matters

Technology cannot solve every phishing problem.

Users still need to understand that a familiar-looking login page does not prove legitimacy.

A valid HTTPS connection does not mean the site is Google’s website.

  1. Cloudflare Does Not Make a Phishing Site Legitimate

The reported use of a Cloudflare-hosted subdomain demonstrates how infrastructure can be abused to make malicious pages appear technically legitimate.

Users should inspect the actual domain rather than relying on the padlock.

  1. The Most Dangerous Attacks May Look Normal

The attacker is not necessarily creating an obviously broken authentication flow.

The victim may experience exactly the type of verification process they have seen many times.

That normality is part of the weapon.

19. Security Teams Should Assume Persistence

When a sophisticated phishing toolkit is involved, investigators should assume the attacker attempted persistence until evidence proves otherwise.

This mindset reduces the chance of prematurely closing the incident.

20. Passkey Inventory Should Become Standard

Organizations should know which passkeys belong to which users and when they were registered.

Unexpected credentials should not disappear into the background.

They should trigger investigation.

21. OAuth Is Another Hidden Door

Attackers do not need to rely solely on passkeys.

OAuth permissions can provide access to cloud resources even after a password has been changed.

Therefore, OAuth review belongs in the same recovery checklist.

22. Mailbox Rules Can Be Silent Persistence

An attacker who creates a forwarding rule may continue receiving sensitive messages without repeatedly logging in.

That makes mailbox configuration just as important as authentication credentials.

23. Recovery Accounts Deserve Special Protection

An attacker who changes recovery information can make future account recovery much harder.

Recovery settings should therefore be verified after compromise.

  1. Business Email Is an Especially Valuable Target

A compromised mailbox can expose invoices, contracts, customer information, internal conversations and password-reset links.

The value of persistent mailbox access can therefore exceed the value of the original stolen credentials.

  1. A $10,000 Toolkit Is a Market Signal

The price matters because it demonstrates that criminals see enough value in advanced phishing infrastructure to pay substantial sums for it.

That indicates continued demand.

26. Cybercrime Vendors Are Selling Outcomes

The criminal buyer does not necessarily care how the toolkit works internally.

They care whether it can deliver access.

This pushes developers toward increasingly automated attack chains.

27. Identity Attacks Will Become More Automated

The next generation of phishing platforms is likely to automate more of the post-login process.

Credential capture may become only the first stage.

Persistence, account discovery and monetization can follow automatically.

28. Defensive Automation Must Catch Up

If attackers can automate credential enrollment within seconds, defenders need automated detection capable of identifying abnormal authentication changes just as quickly.

Manual investigation alone may be too slow.

  1. Security Teams Should Watch for Impossible Sequences

A user logging in from an unusual location and immediately registering a new passkey deserves investigation.

The individual events may appear legitimate.

The sequence may not be.

  1. Context Is Becoming More Important Than Individual Alerts

A single successful login does not necessarily indicate compromise.

A successful login followed by a new authentication credential, recovery change and OAuth grant is a completely different story.

Security platforms need to understand relationships between events.

  1. The Account Configuration Is Part of the Attack Surface

Organizations often protect servers, laptops and networks while overlooking the account configuration itself.

That needs to change.

The identity configuration can become the

32. The Clean Account Definition Must Change

An account is not clean merely because the attacker cannot use the old password.

It is clean when unauthorized access methods and configuration changes have been removed.

33. Incident Response Playbooks Need Updating

Many older playbooks begin and end with:

Reset password.

Revoke sessions.

Enable MFA.

That is no longer enough for advanced identity attacks.

34. Administrators Need Passkey Visibility

If administrators cannot easily determine which passkeys are registered, they cannot confidently investigate passkey-based persistence.

Visibility is therefore a security requirement.

  1. Strong Authentication Is Still the Best Defense

Despite the complexity of this attack, the fundamental defensive lesson remains straightforward.

Prevent the attacker from obtaining the authenticated session.

Phishing-resistant authentication makes that significantly harder.

36. Human Trust Remains the Weakest Link

The attacker ultimately needs the victim to interact with the phishing infrastructure.

Security awareness therefore remains important even in an era of advanced authentication.

37. The Attack Demonstrates a Broader Principle

Whenever an attacker gains legitimate access, they should be assumed capable of changing the environment around that access.

That principle extends beyond Google.

It applies to cloud platforms, SaaS applications and enterprise identity systems.

38. Authentication Recovery Is Becoming Forensic Work

After a sophisticated compromise, restoring an account increasingly requires forensic investigation.

The objective is to reconstruct what happened while the attacker was authenticated.

  1. “Try Another Way” Can Be a Security Lifeline for Attackers

Alternative authentication mechanisms are designed to help legitimate users recover access.

But if an attacker successfully registers their own credential, the same flexibility can become a persistence mechanism.

40. The Biggest Lesson Is Simple

Do not investigate only what the attacker stole. Investigate what the attacker added.

That is the most important lesson from iAuthFlow v2.

✅ iAuthFlow v2 Uses Advanced Phishing Techniques

Confirmed by the cited research. Abnormal Security analyzed a toolkit capable of using browser-in-the-middle techniques to relay authentication activity and obtain authenticated access.

✅ The Demonstration Shows Passkey-Based Persistence

Supported by the

✅ A Password Reset Alone May Not Remove an Attacker-Enrolled Passkey

Technically consistent with how separate authentication credentials operate. Removing the attacker requires checking the account’s registered authentication methods rather than assuming a password reset eliminates every credential.

⚠️ The Exact Passkey Implementation Is Not Confirmed

Important qualification. Abnormal Security discusses Chromium virtual authenticators as a technically plausible mechanism, but the researchers do not definitively establish that iAuthFlow v2 uses that exact implementation.

✅ The Threat Extends Beyond Password Theft

The core security finding is clear. The significant danger is the attacker’s ability to transform temporary authenticated access into persistent access through additional account configuration.

Prediction

(+1) Phishing-Resistant Authentication Will Become Standard

Organizations facing increasingly sophisticated browser-in-the-middle attacks will accelerate adoption of WebAuthn-based authentication, passkeys and hardware-backed security credentials.

(+1) Identity Monitoring Will Become a Core Security Discipline

Security platforms will increasingly monitor passkey registrations, security-key changes, OAuth grants, recovery settings and mailbox configuration alongside traditional login events.

(+1) Automated Detection Will Focus on Suspicious Sequences

Instead of treating every login as an isolated event, security systems will correlate authentication with credential enrollment and account modifications occurring seconds or minutes later.

(-1) Password-Only Recovery Policies Will Become Increasingly Dangerous

Organizations that continue to define account recovery as simply “reset the password and revoke sessions” will remain vulnerable to attackers who establish alternative authentication paths.

(-1) Commercial Phishing Kits Will Become More Sophisticated

The availability of expensive, modular phishing platforms suggests that attackers will continue moving away from simple credential harvesting toward automated persistence, session abuse and identity manipulation.

(+1) The Definition of a Compromised Account Will Change

The future of incident response will increasingly revolve around one question: what did the attacker change while they were inside?

iAuthFlow v2 is a warning that the most dangerous phishing attack may not be the one that steals your password. It may be the one that quietly adds another way for the attacker to come back.

▶️ Related Video (82% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube