Skip to main content
Mallory
MalwareUsed by 2 actors

Darcula

Darcula is a phishing-as-a-service (PhaaS) platform used in large-scale smishing and phishing campaigns. Reporting describes it as a prominent Chinese-language phishing operation, also referred to as Magic Cat in some tracking, and links it to a broader China-based smishing ecosystem associated with the activity cluster known as Smishing Triad. PRODAFT attributes the kit to threat actor LARVA-246 and reports it is advertised via the Telegram channel "xxhcvv / darcula_channel." Darcula has been observed using Apple iMessage, RCS, Google Messages, and other messaging platforms to distribute phishing lures, often impersonating postal services such as USPS, and Google previously assessed Darcula or Magic Cat as accounting for 80% of phishing texts in the United States.

Darcula provides automated phishing page generation and website cloning capabilities. It can generate phishing pages from a supplied legitimate URL with matching HTML and CSS layouts, and later updates allowed customers to clone any brand’s legitimate website to create a phishing version. In 2025, operators added generative AI features that enable creation of customized, multi-language phishing forms, including form generation, field customization, and translation into local languages without coding skills. Google’s reporting on the related ecosystem also describes AI-assisted workflows in which generated code can be converted into fully functioning scam websites, lowering the barrier for low-skill operators.

The platform is associated with financially motivated credential theft and payment fraud. Supporting reporting states that phishing pages seek credit card data, account credentials, one-time passcodes, and other personal information; some campaigns use fake MFA pages and real-time operator interaction to capture authentication codes and bypass multifactor authentication. Stolen payment information has been used to provision cards into digital wallets for unauthorized purchases, and compromised brokerage credentials have been used in stock-manipulation-related fraud. Darcula is described as globally targeting individuals through mobile-focused phishing, with lures localized across languages and regions.

Infrastructure and scale indicators directly mentioned in the content include Netcraft’s disruption metrics since March 2024: more than 25,000 Darcula pages taken down, nearly 31,000 associated IP addresses blocked, and over 90,000 phishing domains flagged. Additional reporting tied to the broader operation states that more than 1.59 million malicious URLs were detected over a five-month period and that millions of phishing messages were observed on Google Messages. Darcula also reportedly shares identical features and templates with another PhaaS platform called Lucid, and Netcraft assesses Darcula, Lucid, and Lighthouse as part of a loosely connected cybercrime ecosystem.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Smishing Triad

The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.

via the hacker newsthehackernews.com
LARVA-246

The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence2

Traditional phishing kits usually focus on harvesting static user passwords. However, modern operators prefer immediate session hijacking and automated credential reuse.

Execution

1 technique
T1059.007JavaScriptEvidence1

The platform replaced static templates with AI-powered page generators and browser automation tools such as Puppeteer. “This enables users to clone legitimate websites by replicating their HTML, CSS, JavaScript, and visual elements using a target website URL.”

Stealth

1 technique
T1036MasqueradingEvidence1

For example, the Darcula platform uses automated page generators to clone real sites instantly. By supplying a legitimate URL, attackers create unique layouts with perfect HTML and CSS.

Credential Access

1 technique
T1557Adversary-in-the-MiddleEvidence1

Within this ecosystem, GTIG has observed a fundamental move away from static password harvesting towards real-time interception and tokenization.

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence1

Within this ecosystem, GTIG has observed a fundamental move away from static password harvesting towards real-time interception and tokenization.

INDICATORS OF COMPROMISE

IOCs tracked for this family

5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching5

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.