Skip to content

Darcula

Darcula is a Chinese-language phishing-as-a-service platform used primarily for large-scale smishing and mobile-focused phishing operations.

Profile source: Mallory opens in a new tab

Darcula

Family profile

Darcula is a Chinese-language phishing-as-a-service platform used primarily for large-scale smishing and mobile-focused phishing operations. It is associated with financially motivated campaigns that impersonate postal, delivery, government, retail, financial, and other trusted brands to steal payment-card data, credentials, personal information, and in some cases multifactor authentication codes. Reporting has linked the platform to the threat actor designation LARVA-246 and to a broader loosely connected smishing ecosystem often referred to as Smishing Triad.

Darcula is notable for industrialized phishing operations rather than a conventional malware payload. The platform supports operator dashboards, template distribution, licensing and activation management, real-time victim interaction, and live streaming of submitted data to backend administration panels. Observed capabilities include collecting victim-entered information in real time, prompting victims for additional verification data such as PINs or one-time codes, and integrating with messaging workflows used to distribute lures at scale. The kit has also used anti-analysis and anti-forensics measures, including selectively serving phishing content only to targeted mobile devices on cellular networks.

Delivery has centered on smishing through SMS, Apple iMessage, and RCS, with lures commonly claiming a package issue, toll problem, or similar urgent account matter. Darcula has been used to impersonate postal and delivery services and has also been described as capable of rapidly cloning legitimate websites. Later updates added generative AI features that allow operators to generate, customize, and translate phishing forms in multiple languages with minimal technical skill, further lowering the barrier to entry for cybercriminals and improving localization at scale.

The platform targets mobile users globally and has been tied to high-volume phishing activity, particularly in the United States and other international markets. Stolen data has been used for financial fraud, including unauthorized digital-wallet provisioning of compromised payment cards. Darcula exemplifies the maturation of phishing infrastructure into a commercial service model that combines scalable lure delivery, real-time operator support, and increasingly automated page generation.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Session Hijacking
  • Spoofing

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 5, 2026
Feed role
Distribution
Host form
0 IP / 4 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Smishing Triad

Since 2025, Road Toll Smishing infrastructure has evolved to use a phish kit called Darcula.

LARVA-246

The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.

MITRE ATT&CK

Darcula in ATT&CK

10 distinct techniques

Reporting

Research mentioning Darcula

Jul 23
Knowbe4

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.

Jul 18
Infosec Writeups

Medium

Jul 15
Techrepublic Com Security

Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts

Jul 14
ReliaQuest

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

Jul 14
Bleeping Computer

New phishing kits target Microsoft 365 accounts, evade MFA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.