Magic Cat is a phishing kit used in the Darcula phishing-as-a-service ecosystem to enable large-scale smishing campaigns and real-time theft of personal and payment-card data. It has been used to impersonate trusted organizations, including postal, government, toll-road, and delivery brands, and is designed to lower the technical barrier for criminal operators by providing a turnkey phishing platform with brand templates, operator tooling, and licensing controls.
The platform targets victims primarily through mobile-focused phishing flows delivered by text-based messaging, including SMS, iMessage, and RCS. Lures commonly claim that a package or delivery is on hold and direct victims to mobile phishing pages that request address details, payment-card information, and in some cases additional verification data such as PIN codes. Magic Cat includes anti-analysis and access-filtering logic intended to restrict phishing pages to mobile devices on cellular networks, hindering casual inspection from desktop environments.
Magic Cat supports real-time interaction between the victim-facing page and backend operators. Victim-entered data is streamed live to an operator dashboard, allowing scammers to monitor submissions as they occur and prompt victims for additional information when needed. The platform also supports SMS gateway integration and broad template-based impersonation across many brands and countries, making it suitable for international fraud operations at scale.
The backend has been observed to include commercial-style activation and license-management functionality. Individual deployments can generate and manage license keys, enforce expiration dates, annotate licenses, and limit the number of phishing templates available to a customer. This indicates that Magic Cat functions not merely as a single phishing kit but as a managed scamware product distributed to other criminals.
Magic Cat has been associated with the Darcula operation, which has been linked to extensive global smishing activity and large-scale theft of payment-card data. Reporting has attributed a substantial share of phishing text-message activity during peak periods to Darcula and tied the ecosystem to Telegram-based criminal communities supporting infrastructure, operations, and monetization. Researchers also identified logic suggesting a possible hidden authorization bypass or developer backdoor in the backend, though the exact intent of that functionality is not definitively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the Telegram group we also found a pinned message with installation instructions for the phishing software itself. We used a spare laptop, followed the instructions and minutes later, we had installed a copy of the same phishing software that had been used against us: Magic Cat.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
This additional encryption acts as an obfuscation layer to hide the inner workings of the phishing protocol.
The sender claims to be the Norwegian Postal Service, informing us that a delivery is on hold until ‘missing’ address details are provided.
The first features were implemented in an effort to ensure the links could only be visited by mobile devices on cellular networks. Such features are often used so security solutions that do not meet these criteria would not be able to inspect the link for malicious content.
The first features were implemented in an effort to ensure the links could only be visited by mobile devices on cellular networks. Such features are often used so security solutions that do not meet these criteria would not be able to inspect the link for malicious content.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service software kit used by the Darcula operation to enable low-skill scammers to impersonate trusted organizations and steal payment card data.
SMS scamware operation used for large-scale payment card theft (credit card harvesting) supported by phone farms and cash-out infrastructure.
Magic Cat is a feature-rich phishing platform used for smishing and large-scale credential and payment-card theft. It impersonates hundreds of brands globally, streams victim-entered data to operators in real time, supports PIN-code requests and SMS gateway integration, includes licensing and activation management, and contains obfuscated Node.js backend logic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.