3 weeks ago
New Pass-Ta-Key Malware Can Steal Google Passkeys
Passwords help us get into our accounts, but many websites now use passkeys, which are like secret digital keys.
Passkeys are supposed to be very safe because the owner usually has to show a fingerprint or type a special code to use them.
Google lets people keep their passkeys on all their devices at the same time.
That is handy because you don't have to make a new passkey every time you buy a new computer.
But bad people have invented a sneaky computer virus called Pass-Ta-Key.
It gets onto Windows computers and quietly talks to the Chrome web browser.
The virus asks Google's computers to create a valid passkey login for the victim.
Nobody gets asked for a fingerprint or a PIN code, so the bad people get the passkeys without any check.
A security company called Malwarebytes warned people about this attack.
The virus comes in three different versions that attack in different ways.
Security research cited by Malwarebytes identified a new malware attack called 'Pass-Ta-Key' targeting Google-synchronised passkeys.
The malware infects Windows computers and presents three possible attack scenarios.
The 'regular' variant of Pass-Ta-Key silently asks Chrome and Google's cloud to create a valid passkey login.
The passkey login is created with no biometric or PIN prompt needed.
The attack exploits Google Password Manager's ability to synchronize passkeys between devices.
- Who
- Hackers using the Pass-Ta-Key malware, with the attack detailed in research cited by Malwarebytes.
- What
- A new malware attack that can steal Google-synchronised passkeys without biometric or PIN prompts.
- Where
- Windows computers infected by the malware, with Chrome and Google's cloud involved in the attack.
- When
- Not specified in the article.
- Why
- To steal passkeys by exploiting the convenience of Google Password Manager's synchronization of passkeys across devices.
Key facts
- Malware name
- Pass-Ta-Key
- Target
- Google-synchronised passkeys
- Affected systems
- Windows computers
- Variants
- Three, with the 'regular' one described in detail
- Method
- Silently asks Chrome and Google's cloud to create a valid passkey login
- Verification bypassed
- Biometric and PIN prompts
- Research reported by
- Malwarebytes
- Vulnerable service
- Google Password Manager passkey synchronization





