Darcula is a Chinese-language phishing-as-a-service platform used primarily for large-scale smishing and mobile-focused phishing operations. It is associated with financially motivated campaigns that impersonate postal, delivery, government, retail, financial, and other trusted brands to steal payment-card data, credentials, personal information, and in some cases multifactor authentication codes. Reporting has linked the platform to the threat actor designation LARVA-246 and to a broader loosely connected smishing ecosystem often referred to as Smishing Triad.
Darcula is notable for industrialized phishing operations rather than a conventional malware payload. The platform supports operator dashboards, template distribution, licensing and activation management, real-time victim interaction, and live streaming of submitted data to backend administration panels. Observed capabilities include collecting victim-entered information in real time, prompting victims for additional verification data such as PINs or one-time codes, and integrating with messaging workflows used to distribute lures at scale. The kit has also used anti-analysis and anti-forensics measures, including selectively serving phishing content only to targeted mobile devices on cellular networks.
Delivery has centered on smishing through SMS, Apple iMessage, and RCS, with lures commonly claiming a package issue, toll problem, or similar urgent account matter. Darcula has been used to impersonate postal and delivery services and has also been described as capable of rapidly cloning legitimate websites. Later updates added generative AI features that allow operators to generate, customize, and translate phishing forms in multiple languages with minimal technical skill, further lowering the barrier to entry for cybercriminals and improving localization at scale.
The platform targets mobile users globally and has been tied to high-volume phishing activity, particularly in the United States and other international markets. Stolen data has been used for financial fraud, including unauthorized digital-wallet provisioning of compromised payment cards. Darcula exemplifies the maturation of phishing infrastructure into a commercial service model that combines scalable lure delivery, real-time operator support, and increasingly automated page generation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2025, Road Toll Smishing infrastructure has evolved to use a phish kit called Darcula.
The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Information that CoGUI collects as part of its victim profiling includes: GeoIP (geographical location of IP address) Language configuration of the browser Browser type (e.g. Chrome) Browser version Monitor screen height and width OS Platform (e.g. win32) If the victim’s browser is running on a mobile device
This technique presents a simulated browser window and address bar inside the phishing page, making the authentication prompt appear to originate from a legitimate Microsoft domain.
The emails contained URLs leading to a credential capture webpage impersonating Raktuen, which was designed to collect user credentials.
The emails contained URLs leading to a credential capture webpage impersonating Raktuen, which was designed to collect user credentials.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit cited as an example of increasingly sophisticated AI-enabled brand impersonation in phishing campaigns.
A prominent phishing operation associated with large-scale phishing text campaigns in the United States.
A Chinese-language phishing-as-a-service platform that uses automated page generation to clone legitimate websites, supporting scalable phishing and real-time credential/token interception campaigns.
Darcula is the name tied to the broader phishing operation/ecosystem and administrator identity around the Magic Cat platform, as observed in database naming and Telegram infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.