BlackForce is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 12, 2025; most recent activity December 22, 2025.
BlackForce is a phishing toolkit/malware family designed to steal credentials and conduct Man-in-the-Browser (MitB) attacks, with built-in capabilities to bypass multifactor authentication. Its emergence highlights a trend toward MFA-bypass capabilities in phishing toolkits, increasing risk to organizations relying on MFA. The kit represents an evolving threat in credential-stealing phishing campaigns that can defeat MFA protections at the user level.
Zscaler has reported on a new phishing kit named 'BlackForce' that utilizes Man-in-the-Browser (MitB) attacks to steal user credentials and circumvent multi-factor authentication (MFA). The kit includes a vetting system…
A new phishing kit named BlackForce has been identified, allowing attackers to steal credentials and bypass multi-factor authentication using advanced Man-in-the-Browser techniques. First observed in August 2025, the…
New phishing kits utilizing artificial intelligence have emerged, capable of bypassing multi-factor authentication (MFA) and stealing credentials on a large scale. These advanced tools represent a significant evolution…