New BlackForce Phishing Kit Lets Attackers Steal Credentials Using MitB Attacks and Bypass MFA
ID: 32109438-c733-525e-b0e2-6467c7d7f563
STIX ID: report--32109438-c733-525e-b0e2-6467c7d7f563
Feed Name: cybersecurityNews.com
BlackForce is a professional phishing kit first observed in August 2025 that performs Man‑in‑the‑Browser attacks to steal credentials and intercept MFA one‑time codes, effectively enabling account takeovers. The kit—sold on Telegram for roughly €200–300 and already used against brands including Disney, Netflix, DHL, and UPS—uses React-based JavaScript with cache-busting, session storage for resilience, anti-analysis filters, and real-time exfiltration to Telegram, with at least five versions documented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
