As cited
Copy frozen at (site build).
threat intel
Technical Analysis of the BlackForce Phishing Kit
Zscaler ThreatLabz analyzed BlackForce, a phishing kit first observed in August 2025 that has impersonated at least 11 brands including Netflix, Disney, and DHL. The kit steals credentials and performs man-in-the-browser attacks to capture one-time tokens and bypass multifactor authentication (MFA) in real time. BlackForce has evolved through at least five versions, moving from a stateless to a stateful architecture with improved evasion techniques, server-side filtering, and dual-channel data exfiltration via command-and-control panels and Telegram.
Why it matters: Security teams defending enterprise users and customers must recognize that BlackForce operators can now bypass MFA protections through live operator takeover, making credential theft alone insufficient for account compromise, and organizations should implement zero trust architecture to limit post-breach lateral movement.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Technical Analysis of the BlackForce Phishing Kit
Zscaler ThreatLabz analyzed BlackForce, a phishing kit first observed in August 2025 that has impersonated at least 11 brands including Netflix, Disney, and DHL. The kit steals credentials and performs man-in-the-browser attacks to capture one-time tokens and bypass multifactor authentication (MFA) in real time. BlackForce has evolved through at least five versions, moving from a stateless to a stateful architecture with improved evasion techniques, server-side filtering, and dual-channel data exfiltration via command-and-control panels and Telegram.
Why it matters: Security teams defending enterprise users and customers must recognize that BlackForce operators can now bypass MFA protections through live operator takeover, making credential theft alone insufficient for account compromise, and organizations should implement zero trust architecture to limit post-breach lateral movement.
- Source published
- First seen by Cybersecurity Tracker