One of the most alarming phishing to emerge in recent years, BlackForce, is now in the spotlight. The kit, released in 2025, has already become particularly popular with cybercriminals for one key reason: it combines ease of use with technical capabilities that until recently were considered the preserve of state-sponsored hackers or specialized APT groups.

The sales ecosystem: A phishing kit available "off the shelf"
BlackForce is available in Telegram channels, with prices that make it accessible even to novice attackers. The fact that it does not require an advanced technical background to exploit it turns an otherwise complex type of attack into a “mass-use product.”
What until a few years ago required specialized tools and custom development is now available as a package that a skilled person can set up in a few minutes.
See also: Hackers impersonated law enforcement to steal Apple account data
The Shift to Man-in-the-Browser Attacks: What's Really Changing
Although most people are familiar with classic phishing pages, BlackForce goes one step further: it incorporates Man-in-the-Browser (MitB). In simple terms, the attacker is no longer limited to collecting passwords, but “checks” and manipulates the victim’s session in real time.
The ability to intercept one-time passwords —considered the most secure physical barrier to attacks—makes BlackForce one of the most dangerous tools of the year. Bypassing MFA has never been so simple or so automated.
Deceptive Technology: When React is Used as a Weapon
One of the most impressive aspects of the platform is its use of legitimate front-end frameworks like React and React Router. Most of the code loaded looks exactly like standard production of a legit web app, which makes it extremely difficult for automated security systems to discern the fraud.
Phishing pages do not display obvious signs of danger, while the use of cache-invalidating hashes ensures that each victim will download the latest version of the malicious script.
See also: ConsentFix: A new variant of the ClickFix phishing attack

How a BlackForce attack progresses step by step
A BlackForce attack is not a simple “code collection.” It consists of a series of actions that resemble a professional operation:
1. Carefully designed bait
The user is taken to a login page that is difficult to distinguish from the real service. The experience is so authentic that no suspicion is raised even when the password is submitted.
2. Immediately inform the perpetrator
The credentials are automatically displayed on the attacker's dashboard, while also being recorded in a private Telegram channel. We're talking about a process that takes a fraction of a second.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
3. Enabling the actual MFA process
The attacker attempts to connect to the real service, causing the system to send a verification code to the victim.
4. Fake MFA page insertion
Here's the "magic" element: BlackForce creates a fake MFA screen directly inside the victim's browser, so that the user unknowingly enters the one-time code.
5. Completing the account takeover
With the MFA code in their hands, the attacker gains full access. From there, anything is possible: changing passwords, retrieving session tokens, using the account for lateral movement or even financial fraud.

The new versions: Durability and anti-analysis techniques
The latest versions of BlackForce are not limited to interception. They integrate:
- save session state to maintain the attack even after refresh
- filtering traffic from cybersecurity-related researchers, sandboxes, and ISPs
- personalized pages per service for maximum persuasiveness
The kit is evolving at a rapid pace, which indicates that it is under active development by the cybercriminal community.
See also: DroidLock malware locks devices and demands ransom
The message to businesses: A simple "don't click on the link" is not enough
The emergence of tools like BlackForce clearly shows that businesses need to move towards models Zero Trust: stricter identity verification, access restriction, real-time behavior monitoring.
Traditional awareness training programs are no longer sufficient against phishing, which operates as a complete real-time interception system. Protection requires a combination of technical solutions, continuous monitoring, and strict access policies.
