Darcula PhaaS: The AI-Powered Phishing Engine That Hijacked 884,000 Credit Cards
Discover how Darcula PhaaS industrialized phishing with AI, stealing 884,000 credit cards via mobile-first attacks across 100+ countries.
Darcula PhaaS: The AI-Powered Phishing Engine That Hijacked 884,000 Credit Cards
In a world defined by connectivity and convenience, a sinister shift is underway. Cybercriminals have automated deception. Not with vague spam emails or crude spoofing, but through a full-stack phishing enterprise called Darcula.
It’s a global, multi-layered Phishing-as-a-Service (PhaaS) platform. From 2023 to 2024, it enabled over 600 cybercriminals to siphon 884,000 credit card details, with 13 million+ malicious link clicks. Behind its slick interface lies a dark web ecosystem engineered for precision, automation and scalability.

What Is Darcula PhaaS?
Darcula is a Phishing-as-a-Service (PhaaS) operation — a full-service, criminal platform that sells phishing kits, automation tools, and dashboards to scammers who want to run cyber attacks with minimal technical skill.
It offers:
- 20,000+ spoofed domains that mimic banks, postal services, e-commerce giants and more.
- 200+ phishing templates that adapt across languages, brands and customer types.
- Support for SMS, RCS, and iMessage delivery, maximizing reach and trust.
In short, it turns phishing into plug-and-play cybercrime.
How the Operation Worked
Multichannel Phishing Delivery
Darcula focuses on mobile-first delivery, taking advantage of how much we rely on our smartphones. Operators send messages via:
- SMS (text messages)
- RCS (Rich Communication Services, like Android’s version of iMessage)
- iMessage (Apple’s proprietary messaging platform)
These messages link to legitimate-looking websites designed to harvest sensitive data.
Advanced Phishing Engine — Magic Cat
At the heart of Darcula is a toolkit called Magic Cat, which handles the heavy lifting:
- Client-side encryption to mask the data exfiltration
- Real-time form input streaming — card data is captured keystroke by keystroke
- OTP (One-Time Password) interception, often streamed as users type it
Mobile-Only Access Design
Desktop visitors are blocked. Darcula wants only mobile users to interact with the fake sites — because mobile devices have fewer defenses and make it harder for analysts to inspect.
![Operator phones loaded with stolen cards [Source: Mnemonic]](https://miro.medium.com/v2/resize:fit:620/0*6OgDgbxc66AcfQDb.jpg)
Operator phones loaded with stolen cards [Source: Mnemonic]
Scope of the Attack
This wasn’t the work of a lone hacker, it was a full-fledged operation:
- 600+ cybercriminals rented the toolkit and infrastructure
- Campaigns ran from late 2023 to mid-2024
- Over 13 million phishing links were clicked
- Resulting in 884,000 stolen credit cards
That stolen data has an estimated value of $150+ million on underground marketplaces.
Magic Cat in Action
Magic Cat is not just a script, it is a sophisticated engine with:
- Obfuscation layers: Uses Base64, MD5, Rabbit encryption to hide code from detection
- Admin dashboards: Campaign stats, device filtering, IP logging and more
- AI integration: Phishing page generator that auto-builds fake brand pages in multiple languages
Who’s Behind It?
Investigations by cybersecurity researchers and journalists traced the toolkit to a 24-year-old developer in Henan, China.
Key findings:
- GitHub and server fingerprints linked to his former software business
- Allegedly sold the core phishing generator under the guise of a “website builder”
- Continued development evident through version updates and Telegram group activity
Operators were found coordinating in private Telegram channels, managing SIM farms, and boasting about profits from stolen credentials.
[embed][Source: BleepingComputer]
Discovery and Disruption
Thanks to researchers from Netcraft, Mnemonic and others:
- Nearly 100,000 domains associated with Darcula have been blocked
- 31,000+ malicious IPs neutralized
- Continuous monitoring feeds intelligence to global law enforcement agencies
Still, the campaign’s footprint remains global, spanning over 100 countries.
Why This Attack Is Different
Darcula marks a shift in the phishing world:
- Mobile-first attacks designed to outsmart traditional detection
- AI-driven phishing page creation lowers the technical bar
- Scale + ease of use = more criminals, faster
It’s phishing, industrialized.
How to Protect against this
- Don’t trust links in unsolicited texts — go directly to official apps or websites
- Monitor for domain spoofing and phishing campaigns targeting your brand
- Educate your customers and staff about phishing red flags
- Invest in SMS firewalling and zero-trust access control
Darcula PhaaS isn’t just a one-off attack, it is a glimpse into the future of cybercrime. As phishing becomes more polished, accessible and mobile-focused, staying informed is your best defense.
Stay One Step Ahead of Cybercriminals!
🔹 The best defense is staying informed and proactive!
🔹 Follow me for more insights on the latest cyber threats, attack trends and security best practices.
🔗 Let’s **connect **and fortify our digital world together!
메타데이터
- post_id
- 6317b5f066ea
- slug
- darcula-phaas-the-ai-powered-phishing-engine-that-hijacked-884-000-credit-cards-6317b5f066ea
- url
- https://medium.com/devsecops-ai/darcula-phaas-the-ai-powered-phishing-engine-that-hijacked-884-000-credit-cards-6317b5f066ea
- canonical_url
- https://medium.com/devsecops-ai/darcula-phaas-the-ai-powered-phishing-engine-that-hijacked-884-000-credit-cards-6317b5f066ea
- author_url
- https://medium.com/@devenchhajed24
- status
- ok
- fetched_at
- 2026-06-20 20:29:01