Home / Technology / New Malware Steals Emails, Locks Accounts Permanently

New Malware Steals Emails, Locks Accounts Permanently

Summary

  • New malware toolkit sold for over $10,000 on dark web forums.
  • Toolcrafts passkeys, giving attackers lasting access to emails.
  • Security experts recommend auditing passkeys, tokens, and mail rules.
New Malware Steals Emails, Locks Accounts Permanently

A newly identified malware toolkit, iAuthFlow v2, is enabling attackers to gain and maintain persistent access to compromised email accounts. This potent tool is reportedly being sold on Russian dark web forums for upwards of $10,000.

iAuthFlow v2 functions primarily as a phishing kit. It tricks users into divulging their login credentials for services like Google, Microsoft, iCloud, and LinkedIn. Once credentials are obtained, the attackers can log in and subsequently create their own passkey, effectively locking the legitimate user out permanently.

Passkeys, designed as a secure alternative to passwords, utilize cryptographic keys for authentication. However, if an attacker can establish their own passkey on a compromised account, it provides a backdoor for ongoing access. Security researchers emphasize the need for users to conduct thorough audits of their email accounts.

Defensive measures recommended include reviewing account security for unauthorized passkeys or security keys, checking for malicious forwarding rules or filters, and verifying changes to recovery options. It is also advised to revoke any suspicious OAuth tokens and investigate audit logs for sign-in activities and authentication methods.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571