Skip to content

Darcula

Darcula is a Chinese-language phishing-as-a-service platform associated with large-scale smishing and mobile-focused phishing operations.

Profile source: Mallory opens in a new tab

Darcula

Family profile

Darcula is a Chinese-language phishing-as-a-service platform associated with large-scale smishing and mobile-focused phishing operations. It is used to create and operate spoofed websites that impersonate trusted brands and services in order to steal credentials, payment card data, one-time passcodes, and other personal information. Reporting links the platform to a broader financially motivated smishing ecosystem sometimes referred to as Smishing Triad, and some research attributes the kit to the threat actor LARVA-246. Darcula has been promoted through Telegram-based criminal channels and has been observed in campaigns impersonating postal and road-toll services, among other brands.

Darcula is notable for lowering the barrier to entry for phishing operators. It provides automated page generation and site-cloning capabilities that can reproduce the appearance of legitimate websites from a supplied URL, including matching layout elements. In 2025, the platform added generative AI features that support multilingual phishing page creation, phishing form generation, field customization, and translation into local languages, enabling less technically skilled actors to rapidly build customized lures.

The platform has been associated with delivery through Apple iMessage, RCS, and SMS-style smishing workflows. Its campaigns are designed for broad consumer targeting and financial fraud, with emphasis on mobile users. Within the wider Chinese-language PhaaS ecosystem, operations using platforms such as Darcula increasingly support real-time interception of authentication data and session-oriented fraud rather than simple static password theft alone. Darcula has also been cited as part of the broader trend of AI-enabled phishing kits that increase the scale, localization, and plausibility of phishing attacks globally.

Capabilities

  • Credential Theft
  • Session Hijacking
  • Spoofing

Observed infrastructure

Last seven days

First activity
Jul 26, 2026
Last activity
Jul 26, 2026
Feed role
Distribution
Host form
0 IP / 49 hostnames

Leading locations

  • HK10
  • US4
  • DE3
  • SG1

Leading providers

  • Alibaba (US) Technology Co., Ltd.10
  • Tencent Building, Kejizhongyi Avenue7
  • Cloudflare, Inc.1

Infrastructure traits

  • Hosting 18
  • Anycast 1

Reported operators

Threat actors

2 named in public reporting
Smishing Triad

Since 2025, Road Toll Smishing infrastructure has evolved to use a phish kit called Darcula.

LARVA-246

The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.

MITRE ATT&CK

Darcula in ATT&CK

8 distinct techniques

Reporting

Research mentioning Darcula

Jul 14
ReliaQuest

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

AI integration in these kits isn't new, but kits like EvilTokens and "Darcula" reflect a growing sophistication in its application.

Jun 12
Bank Info Security

Google Sues Chinese Phishing Service Over Gemini Abuse

Scam texts enabled by these services have flooded phones globally, with one prominent operation, tracked as Darcula or Magic Cat, accounting for 80% of all phishing texts in the United States, according to Google's lawsuit against the group last year.

May 29
Security Online Info

Chinese PhaaS Ecosystem: Rising Multi-Factor Bypass Threat

For example, the Darcula platform uses automated page generators to clone real sites instantly.

May 1
Bank Info Security

Breach Roundup: Surge in Edge Device Zero-Day Exploits

The Darcula phishing-as-a-service platform introduced generative AI features, enabling cybercriminals to create customized, multi-language phishing pages without coding skills, said Netcraft.

Apr 30
Proofpoint

CoGUI Phish Kit Targets Japan with Millions of Messages | Proofpoint US

Since 2025, Road Toll Smishing infrastructure has evolved to use a phish kit called Darcula.

Apr 28
The Hacker News

⚑ Weekly Recap: Critical SAP Exploit, AI-Powered Phishing, Major Breaches, New CVEs & More

The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities to facilitate phishing form generation in various languages, form field customization, and translation of phishing forms into local languages.

Apr 24
The Hacker News

Darcula Adds GenAI to Phishing Toolkit, Lowering the Barrier for Cybercriminals

The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.