logo

New BlackForce Phishing Kit Lets Attackers Steal Credentials Using MitB Attacks and Bypass MFA

ID: 32109438-c733-525e-b0e2-6467c7d7f563

STIX ID: report--32109438-c733-525e-b0e2-6467c7d7f563

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

BlackForce is a professional phishing kit first observed in August 2025 that performs Man‑in‑the‑Browser attacks to steal credentials and intercept MFA one‑time codes, effectively enabling account takeovers. The kit—sold on Telegram for roughly €200–300 and already used against brands including Disney, Netflix, DHL, and UPS—uses React-based JavaScript with cache-busting, session storage for resilience, anti-analysis filters, and real-time exfiltration to Telegram, with at least five versions documented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.