HomeSecurityBlackForce: New phishing kit steals credentials through MitB attacks

BlackForce: New phishing kit steals credentials through MitB attacks

One of the most alarming phishing to emerge in recent years, BlackForce, is now in the spotlight. The kit, released in 2025, has already become particularly popular with cybercriminals for one key reason: it combines ease of use with technical capabilities that until recently were considered the preserve of state-sponsored hackers or specialized APT groups.

BlackForce phishing kit

The sales ecosystem: A phishing kit available "off the shelf"

BlackForce is available in Telegram channels, with prices that make it accessible even to novice attackers. The fact that it does not require an advanced technical background to exploit it turns an otherwise complex type of attack into a “mass-use product.”

What until a few years ago required specialized tools and custom development is now available as a package that a skilled person can set up in a few minutes.

See also: Hackers impersonated law enforcement to steal Apple account data

The Shift to Man-in-the-Browser Attacks: What's Really Changing

Although most people are familiar with classic phishing pages, BlackForce goes one step further: it incorporates Man-in-the-Browser (MitB). In simple terms, the attacker is no longer limited to collecting passwords, but “checks” and manipulates the victim’s session in real time.

The ability to intercept one-time passwords —considered the most secure physical barrier to attacks—makes BlackForce one of the most dangerous tools of the year. Bypassing MFA has never been so simple or so automated.

Deceptive Technology: When React is Used as a Weapon

One of the most impressive aspects of the platform is its use of legitimate front-end frameworks like React and React Router. Most of the code loaded looks exactly like standard production of a legit web app, which makes it extremely difficult for automated security systems to discern the fraud.

Phishing pages do not display obvious signs of danger, while the use of cache-invalidating hashes ensures that each victim will download the latest version of the malicious script.

See also: ConsentFix: A new variant of the ClickFix phishing attack

BlackForce: New phishing kit steals credentials through MitB attacks

How a BlackForce attack progresses step by step

A BlackForce attack is not a simple “code collection.” It consists of a series of actions that resemble a professional operation:

1. Carefully designed bait

The user is taken to a login page that is difficult to distinguish from the real service. The experience is so authentic that no suspicion is raised even when the password is submitted.

2. Immediately inform the perpetrator

The credentials are automatically displayed on the attacker's dashboard, while also being recorded in a private Telegram channel. We're talking about a process that takes a fraction of a second.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

3. Enabling the actual MFA process

The attacker attempts to connect to the real service, causing the system to send a verification code to the victim.

4. Fake MFA page insertion

Here's the "magic" element: BlackForce creates a fake MFA screen directly inside the victim's browser, so that the user unknowingly enters the one-time code.

5. Completing the account takeover

With the MFA code in their hands, the attacker gains full access. From there, anything is possible: changing passwords, retrieving session tokens, using the account for lateral movement or even financial fraud.

BlackForce: New phishing kit steals credentials through MitB attacks

The new versions: Durability and anti-analysis techniques

The latest versions of BlackForce are not limited to interception. They integrate:

  • save session state to maintain the attack even after refresh
  • filtering traffic from cybersecurity-related researchers, sandboxes, and ISPs
  • personalized pages per service for maximum persuasiveness

The kit is evolving at a rapid pace, which indicates that it is under active development by the cybercriminal community.

See also: DroidLock malware locks devices and demands ransom

The message to businesses: A simple "don't click on the link" is not enough

The emergence of tools like BlackForce clearly shows that businesses need to move towards models Zero Trust: stricter identity verification, access restriction, real-time behavior monitoring.

Traditional awareness training programs are no longer sufficient against phishing, which operates as a complete real-time interception system. Protection requires a combination of technical solutions, continuous monitoring, and strict access policies.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS