Security3 min read
A $10,000 phishing kit claims it can plant rogue passkeys after a real login
Abnormal Security described a $10,000 kit sold on Russian forums that uses a browser-in-the-middle flow, then enrolls a rogue passkey once the victim signs in for real. Demos focused on Google; the sellers also advertised iCloud, LinkedIn, and Microsoft.
