LARVA-246 is a financially motivated cybercrime threat actor associated with the Darcula phishing-as-a-service platform. The actor has been linked to large-scale smishing and phishing operations that lower the barrier to entry for downstream criminals by providing ready-made phishing infrastructure and templates. Darcula has been used to impersonate brands and postal services and to mass-target individuals through SMS-based phishing campaigns, including delivery-themed lures. Darcula has evolved to include capabilities that simplify phishing-page creation, including AI-assisted generation of phishing forms, multilingual translation, and customization of form fields without requiring programming expertise. Reporting has also linked the platform to functionality for cloning legitimate brand websites into phishing pages. Darcula has been noted to share features and templates with other phishing-as-a-service offerings such as Lucid, and has been associated with a broader loosely connected China-based smishing ecosystem sometimes referred to as the Smishing Triad. Within that ecosystem, LARVA-246 appears to function as an operator or developer tied to phishing-kit development and commercialization rather than as a purely intrusion-focused espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.