Skip to main content
Mallory
🇨🇳 CN1 malware family

Darcula

Also known asDarcula

Darcula is a Chinese-speaking, Chinese-language cybercriminal phishing-as-a-service (PhaaS) operation also referred to in the provided content as Magic Cat and the Smishing Triad. The group is associated with large-scale smishing and phishing campaigns distributed through SMS and modern messaging platforms including Apple iMessage and Google Messages. Google Threat Intelligence Group assessed that Darcula accounted for 80% of all phishing text messages in the United States during a peak period, and Google filed civil litigation to disrupt the group and seize its infrastructure. The lawsuit content names Chinese national Yucheng Chang as the group’s leader along with 24 other members. The operation provides phishing tooling that lowers the barrier for low-skill scammers. The content states Darcula used software called Magic Cat and a malicious suite called Outsider, with more than 290 prebuilt templates impersonating financial services providers, phone service providers, government agencies, retailers, USPS, IRS, E-ZPass, and other trusted entities. Darcula’s infrastructure has been linked to over 1.59 million malicious URLs observed between November 14, 2025 and April 14, 2026. The platform reportedly offered subscription access, customer support, tutorials, Telegram-based commercialization, dashboards with real-time victim metrics, and phishing pages capable of capturing credentials, payment card data, CVV values, personal information, one-time passwords, and MFA codes. The content also states Darcula added generative AI capabilities to facilitate phishing form generation in multiple languages, form customization, and translation into local languages. Google alleged the operation abused Gemini to generate and refine phishing websites and provided tutorials showing customers how to use Gemini prompts to create scam pages. The tooling allegedly enabled users with little or no technical knowledge to launch polished phishing sites at scale. Darcula has been used in campaigns targeting government organizations, airlines, postal services, and financial services in more than 100 countries. Group-IB observed infrastructure and characteristics associated with Darcula in global fake shipment tracking campaigns, although it did not definitively attribute that activity to a single actor. Reported tactics and techniques in the provided content include mass SMS smishing, impersonation of courier and government brands, mobile-optimized phishing pages, sender spoofing, use of counterfeit domains and typosquatted domains, embedded credential-harvesting scripts, persistent WebSocket connections, real-time keylogging, UUID-based victim session tracking, and theft of payment data for downstream fraud including digital wallet provisioning and unauthorized purchases.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics3 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566×4
Phishing
T1566.003×2
Spearphishing via Service
TA0005
Stealth
1 technique
T1036×2
Masquerading
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

IOCS

Observables

5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables5

Domains, IPs, and hashes tied to this actor, refreshed continuously.