ARCHIVES
Neutralizing RAT-Assisted Passkey Hijacking via the Visual Password System (VPS)
¹ Independent Researcher, B.E Electronics and Telecommunications, Post Graduate in Marketing, Pune, Maharashtra, India.
Published Online: January-April 2026
Pages: 180-182
Cite this article
↗ https://www.doi.org/10.59256/indjcst.20260501025As the cyber security industry transitions to Passkeys (FIDO2/WebAuthn), a critical vulnerability has emerged in cloud-synced recovery flows. Current implementations rely on a static Device PIN for synchronization. Our research identifies the "Sync-Infiltrator" exploit, where an attacker uses a Remote Access Trojan (RAT) to capture this PIN, allowing them to bypass hardware-binding and clone a victim's identity onto an attacker-controlled device.The proposed Visual Password System (VPS) is a dynamic authentication protocol that shifts the "Root of Trust" to the user’s cognitive space. By utilizing a high-entropy pool of say 54 unique graphical assets, a private mental margin, and hidden "Locker Key" positions, the user ensures that no reusable data is ever typed or displayed. The system effectively neutralizes Phishing and RATs through Proactive Credential Rotation and Visual Masking. This paper introduces the Visual Password System (VPS), a cognitive authentication protocol designed to eliminate reusable secrets and resist RAT-based credential harvesting.
Related Articles
2026
Legal Challenges of Agentic AI Systems in Education and Employment Decision-Making
2026
Enhancements and Optimization of the Canny Edge Detection Algorithm
2026
Smart Health Monitoring System for Digital Wellness Using Blink Rate and Posture Detection
2026
Secure Patient Health Records with Aadhaar Authentication and Consent Access
2026
The Role of Digital Accessibility in Enhancing E-Governance in Rural Areas of Sudurpashchim Province, Nepal
2026
Neutralizing RAT-Assisted Passkey Hijacking via the Visual Password System (VPS)
2026
Open Educational Resources in the Indian Context: A Comparative Empirical Analysis with Developed and Developing Countries
2026
Adaptive Fault Tolerance in Machine Learning Systems: A Self-Healing Framework
2026
Integrating Trust Persistence with Reliability Modelling for Failure-Adaptive Distributed Cloud Systems
2026
True Vote: The Future of Fair and Transparent Voting


