Published · 2d agoSecurity2 min read
A $10,000 phishing kit that enrolls its own passkey and survives the password reset
Abnormal AI says iAuthFlow v2 carries a $10,000 base price and uses a relayed Google session to register an operator-controlled passkey. In the seller's demo, a password change did not evict it.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Abnormal AI reports that the iAuthFlow v2 toolkit sells for a $10,000 base price, with additional capability modules sold separately.
- Abnormal researchers have been tracking iAuthFlow v2 since it appeared on a Russian-language cybercrime forum.
- The iAuthFlow v2 build Abnormal examined targets Google; the seller also advertises versions for Microsoft, iCloud, and LinkedIn.
- The attack uses a browser-in-the-middle architecture with two browser environments: the target interacts with a Google-styled phishing page while iAuthFlow v2 controls a separate browser on the attacker's server, relaying the target's credentials and authentication responses into it and sending Google's prompts back.
- Once the attacker-controlled browser has an authenticated Google session, the toolkit can use it to make changes inside the account, including enrolling a new passkey controlled by the operator.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The number is a list price, not an estimate: Abnormal AI says the iAuthFlow v2 phishing toolkit sells for a $10,000 base price, with additional capability modules sold separately [1]. Abnormal has tracked it since it surfaced on a Russian-language cybercrime forum, and the build the firm examined targets Google, while the seller also advertises versions for Microsoft, iCloud, and LinkedIn [2][3].
What the money buys is not credential theft. The kit runs a browser-in-the-middle: the target types into a Google-styled page while a separate browser on the attacker's server does the actual signing in, with prompts relayed back and forth [4]. Once that remote browser holds an authenticated session, the toolkit uses it to act inside the account, including enrolling a new passkey controlled by the operator [5]. In the recorded run, the target was parked on a lure-domain page reading "Verification, Processing" while that work happened [11].
That is the mechanism worth pricing. Normally, when a compromise is limited to a captured session, killing the session and resetting the password ends it [14]. In the seller's demonstration, the owner changed their password, the live session died, and the operator logged back into the mailbox using the passkey they had enrolled [6]. So the standard containment pair does not, as demonstrated, remove this attacker [13].
Supporting detail is unglamorous and cheap: a unique link on a trycloudflare[.]com subdomain from Cloudflare's free tunnel service [7], a device fingerprint applied to the attacker browser before the victim types, and a log recording the email, the password, then an authenticator code 40 seconds later [8]. The test account already had a passkey, and Google offered it alongside the code, but the user chose the code, which the relay passed through [9]. Google's SID and SSID cookies appearing in the attacker browser is the toolkit's success signal [10].
One caveat carried by Abnormal itself: researchers did not run the toolkit or reproduce the attack, working instead from forum posts, a Telegram channel, demonstration videos, and Google's documentation [12].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Abnormal AI reports that the iAuthFlow v2 toolkit sells for a $10,000 base price, with additional capability modules sold separately.
- [2]
Abnormal researchers have been tracking iAuthFlow v2 since it appeared on a Russian-language cybercrime forum.
- [3]
The iAuthFlow v2 build Abnormal examined targets Google; the seller also advertises versions for Microsoft, iCloud, and LinkedIn.
- [4]
The attack uses a browser-in-the-middle architecture with two browser environments: the target interacts with a Google-styled phishing page while iAuthFlow v2 controls a separate browser on the attacker's server, relaying the target's credentials and authentication responses into it and sending Google's prompts back.
- [5]
Once the attacker-controlled browser has an authenticated Google session, the toolkit can use it to make changes inside the account, including enrolling a new passkey controlled by the operator.
- [6]
In the seller's recorded demonstration, the account owner later changed their password, invalidating the active session, but the operator authenticated with the newly enrolled passkey and returned to the mailbox.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- news.risky.biz2d agoAcademics find source code overlaps between Geedge and China's Great Firewall
Cited in this coverage: Abnormal AI
Cited in this coverage: seller's recorded demonstration, as described by Abnormal AI



