logo

Technical Analysis of the BlackForce Phishing Kit

ID: 13309be4-6c9e-55b7-87e3-a3782a393723

STIX ID: report--13309be4-6c9e-55b7-87e3-a3782a393723

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-05-01

...
...

ThreatLabz provides a technical breakdown of the BlackForce phishing kit, a professional JavaScript-based phishing platform that uses production-like React builds, visitor vetting, anti-analysis filters, and stateful session management to harvest credentials and intercept MFA (via MitB/fake MFA pages). Stolen data is routed to a C2 panel and, in earlier versions, directly to Telegram; the platform supports real-time attacker interaction to enable guided account takeover and persistent exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.