- iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts
- Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access
- Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods
Security researchers have discovered a new malware toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.