CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Technical Analysis of the BlackForce Phishing Kit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6272

As cited

Copy frozen at (site build).

threat intel

Technical Analysis of the BlackForce Phishing Kit

Zscaler ThreatLabz analyzed BlackForce, a phishing kit first observed in August 2025 that has impersonated at least 11 brands including Netflix, Disney, and DHL. The kit steals credentials and performs man-in-the-browser attacks to capture one-time tokens and bypass multifactor authentication (MFA) in real time. BlackForce has evolved through at least five versions, moving from a stateless to a stateful architecture with improved evasion techniques, server-side filtering, and dual-channel data exfiltration via command-and-control panels and Telegram.

Why it matters: Security teams defending enterprise users and customers must recognize that BlackForce operators can now bypass MFA protections through live operator takeover, making credential theft alone insufficient for account compromise, and organizations should implement zero trust architecture to limit post-breach lateral movement.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Technical Analysis of the BlackForce Phishing Kit

Zscaler ThreatLabz analyzed BlackForce, a phishing kit first observed in August 2025 that has impersonated at least 11 brands including Netflix, Disney, and DHL. The kit steals credentials and performs man-in-the-browser attacks to capture one-time tokens and bypass multifactor authentication (MFA) in real time. BlackForce has evolved through at least five versions, moving from a stateless to a stateful architecture with improved evasion techniques, server-side filtering, and dual-channel data exfiltration via command-and-control panels and Telegram.

Why it matters: Security teams defending enterprise users and customers must recognize that BlackForce operators can now bypass MFA protections through live operator takeover, making credential theft alone insufficient for account compromise, and organizations should implement zero trust architecture to limit post-breach lateral movement.

VendorsMicrosoftGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary