Darcula is a Chinese-language phishing-as-a-service (PhaaS) operation associated with large-scale smishing and web-phishing campaigns. It is also referred to as Magic Cat, Smishing Triad, and Darcula (Larva-246). The service lowers the barrier to entry for fraud operators by providing phishing templates, counterfeit web infrastructure, campaign management features, and operational support, enabling low-skill affiliates to impersonate trusted brands and public-sector entities at scale. Darcula has been linked to mass SMS phishing campaigns that impersonate postal services, tolling authorities, government organizations, airlines, telecommunications providers, retailers, and financial services. Reporting ties the operation to widespread phishing text activity in the United States and to campaigns affecting victims in more than 100 countries. The group’s phishing workflows are designed to harvest payment card data, personal information, account credentials, and one-time authentication codes, including through fake MFA pages. Operationally, Darcula is known for typosquatting and brand impersonation, mobile-optimized phishing pages, and infrastructure marketed through Telegram-based criminal ecosystems. The platform has offered large numbers of phishing templates and counterfeit domains, and later introduced generative AI features that allow operators to create and localize phishing pages in multiple languages with minimal technical skill. Observed phishing pages associated with the broader Darcula ecosystem have included real-time victim-input capture, session tracking, keylogging, and immediate exfiltration of submitted data. Darcula is financially motivated and functions as a cybercrime service provider rather than a state espionage actor. Its activity centers on credential and payment-data theft in support of fraud and downstream monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prominent Chinese-language phishing operation associated with large-scale phishing text campaigns, including a substantial share of phishing texts targeting users in the United States.
A Chinese-language phishing-as-a-service platform potentially involved in fake shipment tracking phishing campaigns, offering large-scale counterfeit domains and phishing templates commercialized via Telegram for global phishing operations.
中国語圏のサイバー犯罪グループ。フィッシング・アズ・ア・サービス(PhaaS)を用いた大規模スミッシング(SMSフィッシング)で、E-ZPass等の公的/準公的サービスになりすまして被害者を偽サイトへ誘導し、決済情報/認証情報の窃取や不正送金に繋げる。
China-based smishing/phishing operation conducting large-scale impersonation campaigns (e.g., E‑ZPass and USPS) using phishing-as-a-service tooling and purchased phishing kits to harvest credentials and steal funds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.