Sunday, September 27, 2026

Darcula PhaaS: 884,000 Credit Card Details Stolen from 13 Million Global User Clicks

The Darcula group has orchestrated a massive phishing-as-a-service (PhaaS) operation, dubbed Magic Cat, compromising an estimated 884,000 credit card details from over 13 million user interactions worldwide.

This smishing (SMS phishing) campaign, first detected in December 2023, impersonates trusted brands like the Norwegian Postal Service to lure victims into divulging sensitive information.

Sophisticated Phishing-as-a-Service Operation

By exploiting mobile-specific vulnerabilities and deploying advanced anti-forensics techniques, the operation has demonstrated a chilling level of sophistication, targeting millions through SMS, iMessage, and RCS platforms with messages prompting users to update delivery details or pay fictitious fees.

Darcula PhaaS
Not Found message.

The Magic Cat software, uncovered through meticulous reverse-engineering by security researchers, is a feature-rich PhaaS platform designed for non-technical operators to launch phishing campaigns at scale.

It supports impersonation of hundreds of global brands with customizable templates, streams victim data in real-time for immediate exploitation, and integrates seamlessly with SMS gateways for mass distribution.

Technical Depth of the Magic Cat Platform

Researchers bypassed the platform’s anti-forensic measures-such as mobile-only access restrictions and client-side encryption using the Rabbit algorithm via crypto-js-by manipulating User-Agent headers and leveraging cellular network simulations.

Darcula PhaaS
Node.js library

Further investigation revealed encrypted communications via Socket.IO, with data obfuscated through Base64 encoding and MD5 hashing, protecting the phishing protocol from prying eyes.

Shockingly, a potential backdoor in the software’s HTTP request handling was identified, allowing unauthorized access to administrative functions, raising questions about developer intent or oversight.

By deobfuscating backend code with tools like Synchrony, researchers activated an unlicensed copy of Magic Cat in a controlled environment, exposing its full capabilities, including license generation and operator dashboards that facilitate real-time victim interaction.

The Darcula operation, linked to a Chinese-based Telegram group, showcases a professional setup with servers, SIM cards, and devices for mass phishing, alongside brazen displays of illicit gains.

Tracing Darcula’s identity through IP addresses, Passive DNS records, and OSINT tools led to connections with Alibaba Cloud VMs, GitHub profiles, and Chinese phone numbers, culminating in a name tied to Telegram document metadata.

This investigation, reported to law enforcement in January 2024 and shared with Norwegian media, underscores the urgent need for collaborative action from financial institutions, tech giants, and mobile operators to combat such pervasive cyber threats, as Darcula’s low-profile mastermind continues to evade full identification while profiting from global deception.

Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team -> Free Download

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat

Kiteworks has urged customers worldwide to temporarily shut down...

Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials

A new demonstration shows how a locally hosted, uncensored...

OpenAI Says Misaligned AI Agents Hacked Hugging Face and Bypassed Security Controls

OpenAI has disclosed that autonomous AI agents compromised portions...

Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems

San Francisco, USA, September 25th, 2026, CyberNewswire Archipelo today announced...

14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape

A vulnerability in the Linux kernel’s AF_ALG cryptographic interface,...

Related Articles

Recent News