UNC5814 is a cybercriminal cluster linked to Darcula, a Chinese-language phishing-as-a-service platform associated with large-scale credential and payment theft operations. The activity reflects the growth of mature Chinese-language phishing ecosystems that provide operators with turnkey tooling for real-time phishing rather than simple static credential collection. Darcula is notable for using AI-assisted page generation and browser automation to clone legitimate websites dynamically, producing unique phishing pages that reduce the effectiveness of signature-based detection. Operations associated with UNC5814 are designed to capture credentials, one-time passcodes, and payment information in real time, enabling multi-factor authentication bypass and unauthorized access to victims’ financial accounts. The broader ecosystem around this activity uses live administration panels to interact with victims during active phishing sessions and has emphasized digital wallet provisioning and tokenization of stolen payment data. Promotion and coordination have been observed in Chinese-language criminal communities, including Telegram-based channels. Victim targeting has centered on non-Chinese brands and users outside China, with observed campaigns and platform support spanning Japan as well as broader regions in the Americas, Europe, Australia, and the Middle East. The activity is consistent with financially motivated cybercrime focused on phishing-enabled account compromise and downstream fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.