BlackForce Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
December 12, 2025
Last Seen
December 22, 2025

BlackForce is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 12, 2025; most recent activity December 22, 2025.

Overview

BlackForce is a phishing toolkit/malware family designed to steal credentials and conduct Man-in-the-Browser (MitB) attacks, with built-in capabilities to bypass multifactor authentication. Its emergence highlights a trend toward MFA-bypass capabilities in phishing toolkits, increasing risk to organizations relying on MFA. The kit represents an evolving threat in credential-stealing phishing campaigns that can defeat MFA protections at the user level.

Related Threat Clusters

Recent Intelligence Reports

  • New BlackForce Phishing Kit Bypasses Multifactor Authentication — Blog.Knowbe4 · December 22, 2025
  • AI Phishing Kits Evolve: Bypassing MFA and Scaling Cyber Threats — Webpronews · December 12, 2025
  • New BlackForce Phishing Kit Lets Attackers Steal Credentials Using MitB Attacks and Bypass MFA — Cybersecuritynews · December 12, 2025
  • BlackForce Launches New Phishing Kit Enabling MitB Attacks to Steal Credentials and Bypass MFA — Cyberpress · December 12, 2025

CVSS v3.1 Breakdown