The phishing kit adds its own passkey — so resetting the password does not remove the attacker
2026-08-22Security
Abnormal found iAuthFlow V2 selling for $10,000 on Russian-language forums. During the phishing flow it silently registers an attacker-controlled passkey on the victim's account. Passkeys are independent of the password, so the standard remediation — reset, revoke sessions — leaves the intruder logged in.