Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 4, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 2 hostnames
Darcula is a Chinese-language phishing-as-a-service platform associated with large-scale smishing and mobile-focused phishing operations.
Profile source: Mallory opens in a new tabDarcula
Darcula is a Chinese-language phishing-as-a-service platform associated with large-scale smishing and mobile-focused phishing operations. It is used to create and operate spoofed websites that impersonate trusted brands and services in order to steal credentials, payment card data, one-time passcodes, and other personal information. Reporting links the platform to a broader financially motivated smishing ecosystem sometimes referred to as Smishing Triad, and some research attributes the kit to the threat actor LARVA-246. Darcula has been promoted through Telegram-based criminal channels and has been observed in campaigns impersonating postal and road-toll services, among other brands.
Darcula is notable for lowering the barrier to entry for phishing operators. It provides automated page generation and site-cloning capabilities that can reproduce the appearance of legitimate websites from a supplied URL, including matching layout elements. In 2025, the platform added generative AI features that support multilingual phishing page creation, phishing form generation, field customization, and translation into local languages, enabling less technically skilled actors to rapidly build customized lures.
The platform has been associated with delivery through Apple iMessage, RCS, and SMS-style smishing workflows. Its campaigns are designed for broad consumer targeting and financial fraud, with emphasis on mobile users. Within the wider Chinese-language PhaaS ecosystem, operations using platforms such as Darcula increasingly support real-time interception of authentication data and session-oriented fraud rather than simple static password theft alone. Darcula has also been cited as part of the broader trend of AI-enabled phishing kits that increase the scale, localization, and plausibility of phishing attacks globally.
Reported operators
Since 2025, Road Toll Smishing infrastructure has evolved to use a phish kit called Darcula.
The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities.
MITRE ATT&CK
Reporting
Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.