Zscaler has published a report on a new phishing kit dubbed “BlackForce” that uses Man-in-the-Browser (MitB) attacks to steal credentials and bypass multi-factor authentication. Notably, the kit “features a vetting system to qualify targets, after which a live operator takes over to orchestrate a guided compromise.”
Additionally, the phishing kit uses mostly legitimate code in order to avoid detection by security scanners.
“The most effective deception tactic used by the BlackForce phishing kit is its ‘legitimate-looking’ codebase,” Zscaler says. “Our analysis found that more than 99% of the malicious JavaScript file's content consists of production builds of React and React Router, giving it a legitimate appearance.”
The BlackForce attack chain proceeds as follows:
- “The victim clicks on the phishing link and is directed to an attacker-controlled phishing page.
- “A server-side Internet Service Provider (ISP)/vendor blocklist is applied to the victim's IP or User-Agent, blocking any traffic identified as a crawler, scanner.
- “After user validation, the phishing page is served and is designed to appear as a legitimate website.
- “The victim, believing the page is authentic, enters their credentials, which are immediately captured by the attacker.
- “The attacker receives real-time victim session alerts and the exfiltrated credentials to their command-and-control (C2) panel alerting them of a live target. The stolen credentials are also sent to the attacker via a Telegram channel
- “The attacker attempts to log into the legitimate target website using the stolen credentials, triggering an MFA authentication prompt.
- “Using MitB attack techniques, the attacker deploys a fake MFA authentication page to the victim’s browser through the C2 panel”
- “The victim's browser renders the fake MFA page, and the victim, unaware of the attack, enters their MFA code”
Once the attacker has the MFA code, they can gain access to the victim’s account. The victim is then redirected to the legitimate website of the spoofed service.
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.
Zscaler has the story.

