logo

‘Darcula’ PhaaS Campaign Sinks Fangs into Victims

ID: bf5859e3-805b-59f7-bf89-c57abca69718

STIX ID: report--bf5859e3-805b-59f7-bf89-c57abca69718

Feed Name: Security Boulevard

Threat Score
72/100

Date Published: 2024-03-29

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

NetCraft researchers report a prolific phishing-as-a-service platform named “Darcula” that has been used since at least last summer to deploy over 20,000 fraudulent domains targeting postal services and many other trusted brands across 100+ countries. The actors leverage iMessage and RCS to bypass SMS defenses and use modern web tooling (React, Docker, Harbor) to rapidly deploy and update phishing pages, averaging about 120 new domains per day.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.