Darcula is a Chinese-speaking cybercriminal phishing-as-a-service operation focused on large-scale mobile-first smishing and phishing fraud. It is also referred to as Magic Cat, Larva-246, and in some reporting as the Smishing Triad. The operation provides phishing infrastructure, templates, and operator tooling that enable low-skill affiliates or customers to impersonate trusted organizations and harvest victims’ personal information, payment-card data, credentials, and one-time authentication codes. Darcula is known for impersonating postal and delivery services, financial institutions, utilities, government bodies, airlines, telecommunications providers, and tolling or public-service brands. Campaigns commonly use SMS, iMessage, and RCS delivery to lure victims with package-delivery, unpaid-fee, or account-related pretexts. The phishing workflow is optimized for mobile devices and has used anti-analysis and traffic-filtering measures to restrict access to mobile users on cellular networks. Darcula infrastructure has also been associated with typosquatting and large-scale counterfeit domain use. The platform’s tooling has been described as a mature commercial phishing suite with licensing and activation management, template distribution, real-time victim interaction, and administrative dashboards. Magic Cat, a toolkit associated with Darcula, supports live streaming of victim-entered data to operators, real-time requests for additional verification data such as PINs or one-time codes, and broad multi-brand templating across many countries. Reporting also indicates Darcula later added generative AI features to simplify creation, customization, and multilingual translation of phishing pages, further lowering the barrier to entry for operators. Darcula has been linked to Telegram-based criminal communities used for promotion, support, and commercialization of phishing kits and related smishing infrastructure. The actor has been publicly tied to large-scale fraud operations affecting victims in more than 100 countries, including major campaigns impersonating U.S. government and public-service entities. Its activity is financially motivated and centered on theft of payment data and other sensitive information for downstream fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Chinese-speaking phishing kit/platform used for comparison with JWR, sharing behavioral similarities such as live operator puppeteering and OTP interception but not code-level overlap.
Named only as a comparison point among Chinese-speaking phishing kits; not part of the observed campaign.
Mobile-first phishing-as-a-service platform with large-scale brand impersonation and website cloning capabilities, used to harvest personal data, payment-card details, and authentication codes.
A prominent Chinese-language phishing operation associated with large-scale phishing text campaigns, including a substantial share of phishing texts targeting users in the United States.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.