Cybersecurity researchers have identified several new phishing kits – BlackForce, GhostFrame, InboxPrime AI, and Spiderman – that significantly lower the barrier for large-scale credential theft and MFA bypass attacks. These platforms combine advanced evasion techniques, real-time data exfiltration, automated campaign management, and phishing-as-a-service capabilities to target popular consumer brands, Microsoft 365 and Google Workspace accounts, enterprise cloud environments, and European financial institutions.
Rather than requiring advanced technical expertise, many of these kits package sophisticated attack techniques into turnkey offerings that can be operated by relatively inexperienced cybercriminals.

BlackForce enables credential theft and Man-in-the-Browser attacks capable of intercepting usernames, passwords, session cookies, and one-time passwords, allowing attackers to bypass multi-factor authentication before victims realize their accounts have been compromised. Researchers from Zscaler report that the platform impersonates well-known brands, actively filters security scanners and automated analysis systems, and continues to receive regular feature updates from its developers.

InboxPrime AI represents a further escalation by incorporating artificial intelligence into phishing operations. According to Abnormal Security, it automates phishing email generation, personalizes content based on the intended recipient, and produces convincing business communications that closely resemble legitimate corporate correspondence, dramatically increasing the scale and effectiveness of phishing campaigns.

Spiderman focuses on customers of European banks and financial services by delivering highly realistic login portals, multi-stage authentication workflows, and convincing payment verification pages designed to harvest credentials and banking information.

GhostFrame, meanwhile, relies on stealthy iframe-based techniques that dynamically load phishing content only when specific conditions are met, helping campaigns evade both automated security scanners and traditional URL filtering technologies. Researchers from Varonis and Barracuda have linked GhostFrame infrastructure to more than one million phishing attempts, demonstrating how rapidly these kits can be deployed across large-scale campaigns. Separately, ANY.RUN has observed hybrid phishing operations that combine components from multiple phishing kits within a single attack, allowing adversaries to mix credential harvesting, session hijacking, and MFA bypass techniques while making attribution significantly more difficult.

Another notable trend is the increasing emphasis on session theft rather than password theft alone. Modern phishing kits frequently target authentication cookies, OAuth tokens, browser sessions, and temporary access tokens that allow attackers to hijack already authenticated sessions without needing to repeatedly challenge MFA. Many platforms also integrate with Telegram bots, encrypted messaging services, or cloud-hosted command-and-control infrastructure to provide operators with stolen credentials in real time, enabling immediate account takeover before victims or defenders can react.

Collectively, these developments illustrate the continued industrialization of phishing. Automation, AI-assisted content generation, modular architectures, session hijacking, and built-in MFA bypass capabilities have transformed phishing kits into mature criminal platforms that enable highly convincing, scalable campaigns with minimal technical expertise. As these capabilities continue to evolve, organizations should expect phishing operations to become faster, more personalized, and increasingly difficult to distinguish from legitimate communications, reinforcing the importance of prevention-focused security controls that stop malicious content before users ever have the opportunity to interact with it.

1 Zscaler Zscaler is a cloud-based cybersecurity company that provides secure internet access and private application connectivity for enterprises. It is known for pioneering the zero trust network access (ZTNA) model, which replaces traditional perimeter-based security with identity- and context-driven access controls. The company helps organizations protect users, devices, and data across distributed networks.
2 Abnormal Abnormal (also known as Abnormal AI or Abnormal Security) is a cybersecurity company specializing in AI-driven email and cloud application protection. Its platform applies behavioral artificial intelligence to detect and prevent socially engineered attacks such as phishing, business email compromise, and account takeover across enterprise environments. Founded in 2018, Abnormal has rapidly emerged as a leader in behavioral-based security, recognized in the 2024 Gartner Magic Quadrant™ for Email Security Platforms for its completeness of vision and execution.
3 Varonis Varonis is a data security and analytics company that specializes in protecting enterprise data from insider threats and cyberattacks. It focuses on securing unstructured data—such as files, emails, and documents—across on-premises and cloud environments. The company’s software helps organizations detect abnormal user behavior, prevent data breaches, and ensure compliance with privacy regulations.
4 Barracuda Barracuda is an American cybersecurity and data protection company known for providing cloud-enabled security and storage solutions for businesses. Its offerings help organizations secure email, networks, applications, and data against cyberthreats while ensuring compliance and continuity.
5 ANY.RUN ANY.RUN is an interactive malware analysis platform designed to help cybersecurity professionals investigate, detect, and understand malicious software. It provides a cloud-based sandbox environment where users can observe malware behavior in real time, making it a popular tool for threat research and incident response.