Summary
Security researchers have uncovered a new malware toolkit called iAuthFlow v2, sold on Russian forums, that allows attackers to maintain access to email accounts even after password resets by creating attacker-controlled passkeys. The tool primarily functions as a phishing mechanism, tricking users into providing credentials to generate these persistent passkeys. To defend against it, users are advised to audit passkeys, OAuth tokens, mail rules, and remove any unauthorized authentication methods.