A new phishing toolkit uses passwords to maintain access after a password reset

iAuthFlow V2 is a new set of phishing tools demonstrating the rapidly improving sophistication of phishing techniques.

iAuthFlow V2 is a malware toolkit first seen on a Russian-language cybercrime forum. This is an advanced form of phishing that offers permanent access to the victim’s account, surviving password resets.

The base toolkit retails for $10,000, with additional modules sold separately. Using information available from the seller’s forum posts and demos (but without acquiring or running the malware), the rogue researchers postulated analysis of its work based on the “passkey” module and used against a Gmail account.

The target is phished in the normal way, landing on an attacker-controlled web page that is displayed in the target’s browser. The attack requires the slip to be successful and the target tricked into entering credentials. However, undetected by the target, the attacker has a separate but connected second browser environment on the attacker’s own server.

In the normal course of events, the compromise is discovered either quickly or eventually. Standard procedure for the victim is to reset the password, which breaks the attacker’s access. But not if iAuthFlow V2 is the compromise method. As the target interacts with the main phishing page, credentials and authentication responses are passed to the remote browser, which actually responds to the target.

The malware instantly applies a device fingerprint to the target’s browser. Each entry from the target is logged. The malware quietly adds a ready access key and everything is passed to the second browser environment. Google, from the second browser but through the original phishing page, asks the target to authenticate. If the initial chip is successful, the target will do so, but not knowing that this already involves authenticating the attacker-controlled access key.

Advertising. Scroll to continue reading.

When the victim discovers the compromise, resetting the password and canceling the session will usually cut off the attacker’s access – and is the standard response to a phishing compromise.

“Changing passwords and revoking active sessions are standard responses to a compromised mailbox. When a hacker’s access is limited to captured session cookies, these actions typically terminate that access,” Abnormal explains in its analysis of the attack. “Google also states that changing a password overrides app passwords and Gmail-scoped OAuth tokens, although some authorized devices and third-party connections may remain signed in.”

But this process does nothing with the new access key, which is an ID registered to the account, not a token derived from the password. It is now controlled by the attacker and can be used for future access. To regain access, an attacker only needs to “try another way” at login and use the access key without needing to know the password.

It should be emphasized that this analysis by Abnormal is based on the online postings of the iAuthFlow V2 vendor and not on actual malware usage. Gemini describes the malware as “a commercial Phishing as a Service (PhaaS) toolkit/framework marketed and sold to cybercriminals on underground hacking forums (such as the Exploit forum).” No mention of passwords. The co-pilot’s response is even more confusing. So it should be understood that very little is known about iAuthFlow V2.

This lack of public knowledge of the toolkit is understandable given its cost and (if Abnormal is correct) stealth operation. What its existence and Abnormal’s analysis demonstrate, however, is the growing sophistication of social engineering technology.

Abnormal analysis includes IOC and remediation advice. Essentially, this suggests that resetting a password is no longer enough to fix a phisher compromise.

Connected: FBI, Google dismantle ‘Outsider Enterprise’ phishing service.

Connected: MokN raises $15 million for Phish-Back platform

Connected: Over 500 organizations affected in long-running phishing campaign

Connected: Microsoft warns of sophisticated phishing campaign targeting organizations in the US

Leave a Reply

Your email address will not be published. Required fields are marked *