Researchers exposed two closely related smishing operations that impersonated parcel-delivery brands and used phishing kits with live operator consoles to steal identity and payment-card data. In one case, investigators tied a J&T Express lure to a short-lived domain, jtexpress.mwkqbr[.]club, and found a kit that harvested full identity details and card information before relaying victims into OTP, PIN, app, email, or CVV challenge screens. Static analysis showed AES-128-CBC encryption in browser storage and socket transport, a Socket.IO relay on the /com/socket.io/ path, multiple client-side verification routes, and Chinese debug strings, while the infrastructure was registered through Dominet (HK) Limited and fronted by Cloudflare before being suspended days later.
The findings mirror a broader investigation into Darcula and its Magic Cat phishing platform, which used smishing messages posing as postal and delivery services and streamed victim data in real time to an operator “admin” room. Researchers said the platform functioned as a mature phishing-as-a-service business with licensing, activation management, template distribution, real-time victim interaction, and possible backdoor capability, and linked it to Telegram communities and large-scale criminal monetization. The combined reporting indicates an industrialized ecosystem in which human operators actively guide victims through bank verification steps, allowing attackers to bypass 3D Secure protections and compromise hundreds of thousands of targets.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The phishing domain mwkqbr.club was placed on clientHold and suspended four days after registration. This disrupted the J&T Express impersonation campaign hosted on the domain.
Cloudflare delegation for mwkqbr.club landed after the domain registration, placing the phishing infrastructure behind Cloudflare. This marked the domain becoming operationally staged for the campaign.
The domain mwkqbr.club, used for a J&T Express-themed smishing campaign, was registered through Dominet (HK) Limited. The phishing URL later used the path jtexpress.mwkqbr[.]club/com.
After investigating the Darcula phishing-as-a-service operation and the Magic Cat phishing kit, researchers compiled a report and shared it with several law enforcement agencies. The article explicitly states this reporting occurred in January 2024.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcemnemonic.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.