Darcula is a Chinese-language phishing-as-a-service platform associated with large-scale smishing and mobile-focused phishing operations. It is used to create and operate spoofed websites that impersonate trusted brands and services in order to steal credentials, payment card data, one-time passcodes, and other personal information. Reporting links the platform to a broader financially motivated smishing ecosystem sometimes referred to as Smishing Triad, and some research attributes the kit to the threat actor LARVA-246. Darcula has been promoted through Telegram-based criminal channels and has been observed in campaigns impersonating postal and road-toll services, among other brands.
Darcula is notable for lowering the barrier to entry for phishing operators. It provides automated page generation and site-cloning capabilities that can reproduce the appearance of legitimate websites from a supplied URL, including matching layout elements. In 2025, the platform added generative AI features that support multilingual phishing page creation, phishing form generation, field customization, and translation into local languages, enabling less technically skilled actors to rapidly build customized lures.
The platform has been associated with delivery through Apple iMessage, RCS, and SMS-style smishing workflows. Its campaigns are designed for broad consumer targeting and financial fraud, with emphasis on mobile users. Within the wider Chinese-language PhaaS ecosystem, operations using platforms such as Darcula increasingly support real-time interception of authentication data and session-oriented fraud rather than simple static password theft alone. Darcula has also been cited as part of the broader trend of AI-enabled phishing kits that increase the scale, localization, and plausibility of phishing attacks globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2025, Road Toll Smishing infrastructure has evolved to use a phish kit called Darcula.
The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Information that CoGUI collects as part of its victim profiling includes: GeoIP (geographical location of IP address) Language configuration of the browser Browser type (e.g. Chrome) Browser version Monitor screen height and width OS Platform (e.g. win32) If the victim’s browser is running on a mobile device
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit cited as an example of increasingly sophisticated AI-enabled brand impersonation in phishing campaigns.
A prominent phishing operation associated with large-scale phishing text campaigns in the United States.
A Chinese-language phishing-as-a-service platform that uses automated page generation to clone legitimate websites, supporting scalable phishing and real-time credential/token interception campaigns.
Phishing-as-a-service platform that leverages generative AI to create convincing, multi-language phishing pages, primarily delivered via iMessage and RCS for smishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.