ARCHIVES

Original Article

Neutralizing RAT-Assisted Passkey Hijacking via the Visual Password System (VPS)

Aniket Chandramohan Deshpande1
1 Independent Researcher, B.E Electronics and Telecommunications, Post Graduate in Marketing, Pune, Maharashtra, India.

Published Online: January-April 2026

Pages: 180-182

Abstract

As the cyber security industry transitions to Passkeys (FIDO2/WebAuthn), a critical vulnerability has emerged in cloud-synced recovery flows. Current implementations rely on a static Device PIN for synchronization. Our research identifies the "Sync-Infiltrator" exploit, where an attacker uses a Remote Access Trojan (RAT) to capture this PIN, allowing them to bypass hardware-binding and clone a victim's identity onto an attacker-controlled device.The proposed Visual Password System (VPS) is a dynamic authentication protocol that shifts the "Root of Trust" to the user’s cognitive space. By utilizing a high-entropy pool of say 54 unique graphical assets, a private mental margin, and hidden "Locker Key" positions, the user ensures that no reusable data is ever typed or displayed. The system effectively neutralizes Phishing and RATs through Proactive Credential Rotation and Visual Masking. This paper introduces the Visual Password System (VPS), a cognitive authentication protocol designed to eliminate reusable secrets and resist RAT-based credential harvesting.

Related Articles

2026

Artificial Intelligence in Learning and Teaching

2026

Admin Assist: An AI – Driven Configuration and Orchestration for Enterprise Application

2026

Enhancing Blood Group Identification using pigeon inspired optimization: An Innovative Approach

2026

Eco-Genius: Power Up Smart, Power Down Waste

2026

Crowd-Sourced Disaster Response and Rescue Assistant

2026

Unveiling Deepfake Detection Using Vision Transformers: A Survey and Experimental Study

Share Article

X
LinkedIn
Facebook
WhatsApp

Or copy link

https://test.indjcst.com/archives/10.59256/indjcst.20260501025

*Instagram doesn't support direct link sharing from web. Copy the link and share it in your Instagram story or post.