‘Darcula’ PhaaS Campaign Sinks Fangs into Victims
ID: bf5859e3-805b-59f7-bf89-c57abca69718
STIX ID: report--bf5859e3-805b-59f7-bf89-c57abca69718
Feed Name: Security Boulevard
Threat Score
NetCraft researchers report a prolific phishing-as-a-service platform named “Darcula” that has been used since at least last summer to deploy over 20,000 fraudulent domains targeting postal services and many other trusted brands across 100+ countries. The actors leverage iMessage and RCS to bypass SMS defenses and use modern web tooling (React, Docker, Harbor) to rapidly deploy and update phishing pages, averaging about 120 new domains per day.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
