What Darcula Reveals About Industrialized Smishing

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    A single platform gave 600 criminal groups the ability to impersonate 200 brands across 100 countries through messaging channels that bypass every SMS filter in existence.

    In May 2025, the Norwegian cybersecurity firm Mnemonic, working with journalists at NRK, BR, and Le Monde, published the results of an investigation that had been running for over a year. The subject was Darcula, a Chinese-language phishing-as-a-service platform built for smishing at industrial scale. The investigation traced the platform’s core toolkit, called Magic Cat, to a 24-year-old developer from Henan, China, and what the researchers found was not a single phishing campaign but an entire production environment.

    Darcula maintained more than 20,000 counterfeit domains and over 200 phishing templates covering brands in more than 100 countries: postal services, financial institutions, government agencies, airlines, telecommunications providers. Approximately 600 criminal groups operated on the platform, most communicating through closed Telegram channels in Chinese. Infosecurity Magazine reported that during a seven-month period between 2023 and 2024, the operation compromised 884,000 payment cards. More than 13 million people clicked the links embedded in the messages. In Norway alone, 138,000 clicks produced 19,000 card submissions.

    The numbers are striking, but the operational model is what matters for understanding where smishing is heading.

    Why carrier-native messaging changes the math

    Darcula’s most consequential design choice was to abandon traditional SMS in favor of Apple iMessage and Google’s Rich Communication Services protocol. That distinction matters for reasons that go beyond delivery mechanics.

    Traditional smishing campaigns rely on SMS, which means they pass through carrier networks where filtering and blocking tools operate. Major carriers have invested significantly in SMS spam detection, and organizations like the campaign registries coordinated through the CTIA have created infrastructure to identify and suppress bulk fraudulent messaging. Darcula routes around all of it. iMessage and RCS are encrypted end-to-end and delivered over data connections rather than the carrier SMS path. The messages arrive in the same app, in the same thread, as legitimate communications from contacts the recipient trusts, but they are invisible to the carrier-level filtering that intercepts traditional smishing.

    The economic incentive compounds the evasion advantage. Traditional SMS campaigns incur per-message charges that scale with volume, which means an operation targeting millions of recipients across dozens of countries faces real cost constraints. iMessage and RCS remove those constraints entirely. The messages travel over data connections at effectively zero marginal cost, and Darcula’s operators exploited that difference to reach 13 million clicks without the per-message economics that would have throttled a conventional smishing campaign.

    The platform also incorporated anti-analysis techniques that protected the phishing infrastructure from detection and takedown. Pages served different content depending on whether the visitor arrived from a mobile device or a desktop browser, returning a “Not Found” page to desktop visitors and security scanners while presenting the phishing content only to mobile users arriving through the smishing link. The Hacker News reported that since March 2024, industry efforts had led to the takedown of over 25,000 Darcula-related phishing pages, the blocking of nearly 31,000 IP addresses, and the identification of more than 90,000 phishing domains. The scale of the response reflects the scale of the problem.

    From template library to brand cloning engine

    Darcula’s original 200-template library was already substantial, but the platform did not stop there.

    In early 2025, the developers released version 3, called darcula-suite, which replaced the fixed template library with an automated brand-cloning capability. An operator enters the URL of any brand’s website. The platform uses browser automation to scrape the page’s HTML, images, and stylesheets, then reconstructs a phishing replica that matches the original’s design, layout, and functionality. Dark Reading reported that the upgrade removed the 200-brand limitation entirely: any brand, in any country, could be cloned in minutes without the operator writing a line of code.

    A subsequent update added generative AI integration, enabling operators to generate phishing forms in multiple languages and localize campaigns for any market without manual translation. The template library had imposed a natural ceiling: 200 brands, however broad their geographic reach. The cloning engine and AI localization together removed that ceiling entirely.

    For brand protection teams, this is a qualitative shift. A fixed template library means a defined set of impersonated brands that can be monitored and defended. An automated cloning engine means any brand can become a target at any time, with no advance signal in the template library to indicate it is coming.

    What this tells us about the PhaaS supply chain

    Darcula does not operate in isolation. Mnemonic’s investigation and subsequent reporting identified it as part of a loosely connected ecosystem that includes Lucid and Lighthouse, platforms that share features, templates, and operator communities. The broader network is associated with a cluster of activity researchers call the Smishing Triad, operating primarily out of China but targeting victims globally.

    The ecosystem has the structure of a franchise. At the center, a developer builds and maintains the Magic Cat toolkit. Around it, approximately 600 operator groups subscribe and run their own campaigns, each targeting different brands in different countries, with SIM farms extending their messaging reach and card terminals processing the stolen payment details. The separation of roles is what gives the model its resilience: the developer earns from subscriptions regardless of whether any individual campaign succeeds, and the operators can scale the operation far beyond what any single criminal group could sustain on its own.

    This franchise model is what makes platforms like Darcula resistant to conventional disruption. Taking down phishing pages addresses the output of the platform but does not affect the toolkit that generates them. Identifying and blocking domains addresses the infrastructure but not the messaging channels that deliver the links. Even identifying the developer, as Mnemonic did, does not immediately dismantle the operator network that has built its own campaigns on top of the platform. The supply chain has enough separation between its layers that disrupting one does not cascade through the others.

    The Bottom Line

    Darcula is not a phishing campaign but a production environment that enabled 600 criminal groups to impersonate hundreds of brands across 100 countries through messaging channels that most security tools were not built to monitor. The shift from SMS to carrier-native messaging, the evolution from fixed templates to automated brand cloning, and the integration of generative AI for localization all point in the same direction: brand impersonation infrastructure is becoming more accessible, more scalable, and harder to detect with each iteration. For organizations whose brands were among the 200 in the original library, the threat was already active. For every other organization, the V3 upgrade means the threat is now available on demand.

    Key Takeaways

    What is Darcula?

    A Chinese-language phishing-as-a-service platform designed for smishing at scale. It maintained 20,000+ counterfeit domains and 200+ brand templates, used by approximately 600 criminal groups to target victims in 100+ countries through iMessage and RCS messaging.

    How many victims did Darcula produce?

     During a seven-month period between 2023 and 2024, the operation compromised 884,000 payment cards. More than 13 million people clicked links in the smishing messages. In Norway alone, 19,000 people submitted card details on the phishing pages.

    Why does Darcula use iMessage and RCS instead of SMS?

    Carrier-native messaging channels bypass the SMS firewalls and carrier filtering that intercept traditional smishing. The messages are encrypted, delivered over data connections, and arrive in the same app as legitimate communications. They also avoid per-message SMS charges, removing the cost constraint that limits traditional campaign scale.

    What changed with Darcula version 3?

    The V3 upgrade replaced the fixed 200-template library with automated brand cloning. Operators enter any brand’s URL, and the platform scrapes and reconstructs a phishing replica in minutes. A subsequent update added generative AI for multilingual form generation. Any brand can now be targeted without the operator writing code.

    What should brand protection teams take from this?

    Darcula demonstrates that smishing-based brand impersonation has industrialized. Fixed template libraries are being replaced by automated cloning engines, messaging channels are shifting beyond the reach of SMS filtering, and the franchise model separating developers from operators makes the supply chain resistant to conventional takedown. Monitoring needs to extend to carrier-native messaging channels, and detection needs to account for the speed at which new brand replicas can be generated.

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.