logo

'Darcula' Phishing-as-a-Service Operation Bleeds Victims Worldwide

ID: b31ea550-2416-5442-98fd-e512eb67bdf5

STIX ID: report--b31ea550-2416-5442-98fd-e512eb67bdf5

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-03-27

Date Updated: 2026-04-21

Author: John Leyden, Contributing Writer

...
...

Darcula is a Chinese-language phishing-as-a-service platform powering a widespread global package-delivery smishing campaign, with researchers attributing approximately 19,000 phishing domains across 100+ countries and an average of ~120 new domains per day; the service offers subscription access to ~200 templates, uses modern web technologies (React, Docker) and container registry Harbor, and leverages iMessage/RCS to bypass SMS defenses while primarily targeting postal services and other consumer-facing brands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.