Blog.Knowbe4
BlackForce Phishing Kit Bypasses MFA with Man-in-the-Browser Attacks
First seen 22 Dec 2025, 15:59 UTC
•
•83% similarity
•45.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Zscaler has reported on a new phishing kit named 'BlackForce' that utilizes Man-in-the-Browser (MitB) attacks to steal user credentials and circumvent multi-factor authentication (MFA). The kit includes a vetting system to identify targets, allowing a live operator to manage the compromise process directly. This development poses a significant risk to organizations relying on MFA for security.
ThreatCluster AI