A $10,000 phishing kit claims it can plant rogue passkeys after a real login
Abnormal Security described a $10,000 kit sold on Russian forums that uses a browser-in-the-middle flow, then enrolls a rogue passkey once the victim signs in for real. Demos focused on Google; the sellers also advertised iCloud, LinkedIn, and Microsoft.

On August 21 The Register reported Abnormal Security’s write-up of a $10,000 phishing kit advertised on Russian forums. The kit sits in a browser-in-the-middle position and enrolls a rogue passkey after the victim completes a real login.
What we know
- Abnormal Security described a $10,000 phishing kit sold on Russian forums that uses a browser-in-the-middle flow.
- After a real login, the kit enrolls a rogue passkey; demos focused on Google, and sellers also advertised iCloud, LinkedIn, and Microsoft.
- In one run, a passkey was created six seconds after authentication.
- Recovery, the report said, must remove rogue passkeys, OAuth grants, recovery methods, and mailbox rules.
Takeaways
- A completed login is not the end of the theft if a rogue passkey is enrolled immediately after.
- Sellers pitched Google first and also named iCloud, LinkedIn, and Microsoft.
- Cleanup has to cover passkeys, OAuth grants, recovery methods, and mailbox rules.
Source: The Register


