Darcula is a Chinese-language phishing-as-a-service operation and associated cybercriminal ecosystem focused on large-scale mobile-first smishing and phishing fraud. It is also referred to as Magic Cat and has been associated with the alias Larva-246; some reporting also links it to the broader Smishing Triad nomenclature. The platform lowers the barrier to entry for fraud operators by providing ready-made phishing templates, infrastructure, and campaign tooling that impersonate postal services, financial institutions, utilities, government bodies, airlines, and telecommunications providers across many countries. Darcula is known for mass SMS-driven phishing campaigns that direct victims to mobile-optimized credential and payment-card harvesting pages. Its kits support cloning legitimate websites, customization of phishing forms, multilingual localization, and real-time collection of victim data such as personal details, payment-card information, and one-time authentication codes. Reporting has also described persistent WebSocket-based collection mechanisms and typosquatting usage in campaigns associated with the ecosystem. In 2025 and 2026, the platform reportedly added generative AI features to help operators create and translate phishing pages without coding skills, further industrializing phishing operations. The actor has been tied to widespread smishing activity impersonating U.S. government and toll-related entities as well as postal and courier brands globally. Public reporting and civil litigation have identified Chinese nationals among the operators, including Yucheng Chang as an alleged leader. Darcula has been promoted through Telegram channels and commercialized as a service for other criminals, enabling broad fraud activity rather than narrowly targeted intrusions. Its dominant objective is theft of payment data, credentials, and other victim information for downstream financial fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Chinese-speaking phishing kit/platform used for comparison with JWR, sharing behavioral similarities such as live operator puppeteering and OTP interception but not code-level overlap.
Named only as a comparison point among Chinese-speaking phishing kits; not part of the observed campaign.
Mobile-first phishing-as-a-service platform with large-scale brand impersonation and website cloning capabilities, used to harvest personal data, payment-card details, and authentication codes.
A prominent Chinese-language phishing operation associated with large-scale phishing text campaigns, including a substantial share of phishing texts targeting users in the United States.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.