How Malware Uses Google Passkeys to Maintain Email Access After Password Resets

A novel malware toolkit hijacks email accounts by creating attacker-controlled passkeys, persisting access beyond password changes and session terminations. Learn how to detect and remove these hidden threats.

How Malware Uses Google Passkeys to Maintain Email Access After Password Resets
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What makes this malware threat different from usual email compromises?

Traditional email account breaches can often be neutralized by changing the password and terminating all active sessions. However, the emergence of malware that can bind persistent access through alternative authentication methods challenges this assumption.

This malware toolkit allows attackers to covertly generate passkeys—cryptographic authentication credentials linked to the account—on behalf of themselves. These passkeys allow them to regain entry even after you reset your password and log out all sessions, meaning that typical incident responses may not fully secure affected accounts.

How do attacker-controlled passkeys bypass traditional security measures?

iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets |  Abnormal AI
iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets | Abnormal AI

Passkeys eliminate passwords by using secure cryptographic keys stored on a user’s device, often unlocked by biometrics or PINs. They are designed to be highly resistant to phishing since the keys never leave the device.

Unfortunately, if an attacker tricks a user during login via phishing or a similar tactic, they can silently create a new passkey linked to a device controlled by the attacker. This gives the attacker persistent access that won't be revoked by changing your password alone.

Steps to detect and remove attacker passkeys and maintain account security

  1. Audit Your Account Authentication Methods: Check for unexpected passkeys, security keys, or devices registered to your account.
  2. Review Email Settings: Look for suspicious mail filters or forwarding rules that could divert your email without your knowledge.
  3. Check Account Recovery Options and Delegated Access: Ensure no unauthorized recovery methods or users have been added.
  4. Revoke Third-Party Access: Remove OAuth tokens, unauthorized apps, and revoke permissions granted to suspicious services.
  5. Inspect Multi-Factor Authentication Methods: Validate 2-Step Verification settings and remove any unfamiliar devices or methods.
  6. Monitor Audit Logs: Review sign-in activities and changes to security settings for unusual or unauthorized actions.

What users need to know and do to protect themselves effectively

Google Password Manager Attacks Could Let Malware Hijack…
Google Password Manager Attacks Could Let Malware Hijack…

Relying exclusively on password changes after suspected breaches is no longer sufficient. Users must take a comprehensive approach by examining all authentication and account settings regularly.

Awareness of passkey mechanisms, along with diligent auditing of all linked devices and security methods, is vital to prevent persistent unauthorized access. Employing trusted security software and staying vigilant against phishing attempts remains a cornerstone of defense.

Overall, safeguarding your account now requires a broader security hygiene that encompasses passkeys, OAuth tokens, mail configurations, and multi-factor authentication methods to truly lock out attackers.

React to this story

Related Posts