logo

Darcula Phishing Network Leveraging RCS and iMessage to Evade Detection

ID: 9109a4ae-a187-5249-b551-e6cb83fa2518

STIX ID: report--9109a4ae-a187-5249-b551-e6cb83fa2518

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-03-28

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Darcula is a Chinese-language phishing-as-a-service platform actively enabling smishing and web-phishing across 100+ countries by providing ~200 templates and over 20,000 spoofed domains hosted across thousands of IPs; it leverages iMessage and RCS to evade network filters, uses cloaking and remote kit updates to resist takedowns, and supports large-scale credential and financial fraud often tied to MFA fatigue and SIM/eSIM swapping techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.