BlackForce Phishing Kit Bypasses MFA with Man-in-the-Browser Attacks

BlackForce Phishing Kit Bypasses MFA with Man-in-the-Browser Attacks

First seen 22 Dec 2025, 15:59 UTC Blog.Knowbe4 83% similarity 45.7

Article Content

Browse articles
ThreatCluster

Zscaler has reported on a new phishing kit named 'BlackForce' that utilizes Man-in-the-Browser (MitB) attacks to steal user credentials and circumvent multi-factor authentication (MFA). The kit includes a vetting system to identify targets, allowing a live operator to manage the compromise process directly. This development poses a significant risk to organizations relying on MFA for security.

ThreatCluster AI

Community

Browse all →

Tracked Entities in This Story