logo

New BlackForce Phishing Kit Bypasses Multifactor Authentication

ID: 4b63f74b-adda-5823-acd3-cea2faf47e9d

STIX ID: report--4b63f74b-adda-5823-acd3-cea2faf47e9d

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2025-12-22

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Zscaler reports on the BlackForce phishing kit, which conducts targeted phishing with a vetting system and live operator takeover to capture credentials and bypass multi-factor authentication using Man-in-the-Browser techniques; attackers receive real-time alerts and exfiltrate data (including via Telegram), while the kit evades detection by incorporating legitimate React code to appear benign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.