Darcula
Darcula is a Chinese-speaking, Chinese-language cybercriminal phishing-as-a-service (PhaaS) operation also referred to in the provided content as Magic Cat and the Smishing Triad. The group is associated with large-scale smishing and phishing campaigns distributed through SMS and modern messaging platforms including Apple iMessage and Google Messages. Google Threat Intelligence Group assessed that Darcula accounted for 80% of all phishing text messages in the United States during a peak period, and Google filed civil litigation to disrupt the group and seize its infrastructure. The lawsuit content names Chinese national Yucheng Chang as the group’s leader along with 24 other members. The operation provides phishing tooling that lowers the barrier for low-skill scammers. The content states Darcula used software called Magic Cat and a malicious suite called Outsider, with more than 290 prebuilt templates impersonating financial services providers, phone service providers, government agencies, retailers, USPS, IRS, E-ZPass, and other trusted entities. Darcula’s infrastructure has been linked to over 1.59 million malicious URLs observed between November 14, 2025 and April 14, 2026. The platform reportedly offered subscription access, customer support, tutorials, Telegram-based commercialization, dashboards with real-time victim metrics, and phishing pages capable of capturing credentials, payment card data, CVV values, personal information, one-time passwords, and MFA codes. The content also states Darcula added generative AI capabilities to facilitate phishing form generation in multiple languages, form customization, and translation into local languages. Google alleged the operation abused Gemini to generate and refine phishing websites and provided tutorials showing customers how to use Gemini prompts to create scam pages. The tooling allegedly enabled users with little or no technical knowledge to launch polished phishing sites at scale. Darcula has been used in campaigns targeting government organizations, airlines, postal services, and financial services in more than 100 countries. Group-IB observed infrastructure and characteristics associated with Darcula in global fake shipment tracking campaigns, although it did not definitively attribute that activity to a single actor. Reported tactics and techniques in the provided content include mass SMS smishing, impersonation of courier and government brands, mobile-optimized phishing pages, sender spoofing, use of counterfeit domains and typosquatted domains, embedded credential-harvesting scripts, persistent WebSocket connections, real-time keylogging, UUID-based victim session tracking, and theft of payment data for downstream fraud including digital wallet provisioning and unauthorized purchases.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prominent Chinese-language phishing operation associated with large-scale phishing text campaigns, including a substantial share of phishing texts targeting users in the United States.
A Chinese-language phishing-as-a-service platform potentially involved in fake shipment tracking phishing campaigns, offering large-scale counterfeit domains and phishing templates commercialized via Telegram for global phishing operations.
中国語圏のサイバー犯罪グループ。フィッシング・アズ・ア・サービス(PhaaS)を用いた大規模スミッシング(SMSフィッシング)で、E-ZPass等の公的/準公的サービスになりすまして被害者を偽サイトへ誘導し、決済情報/認証情報の窃取や不正送金に繋げる。
China-based smishing/phishing operation conducting large-scale impersonation campaigns (e.g., E‑ZPass and USPS) using phishing-as-a-service tooling and purchased phishing kits to harvest credentials and steal funds.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.