This dastardly phishing attack has stolen nearly a million credit cards – here’s how to stay safe


- Around 600 threat actors are using Darcula, experts warn
- They have managed to steal more than 800,000 credit card details in less than a year
- Mobile devices are prime targets for phishing nowadays
Darcula, an infamous Phishing-as-a-Service (PhaaS) kit, has helped hundreds of its users steal almost a million credit cards in roughly half a year’s time, cybersecurity researchers have said.
Analysts from NRK, Bayerischer Rundfunk, Le Monde, and Norwegian security firm Mnemonic have been drilling deep into Darcula, which in just seven months between 2023 and 2024 served some 600 operators.
The hackers were able to generate 13 million clicks on malicious links sent via text messages to targets worldwide – and as a result, were able to steal 884,000 credit cards.
Generative AI threats
Apparently, Darcula is focused on mobile platforms – Android and iOS, and uses 20,000 domains and can easily spoof well-known brands.
It stands out from other similar platforms by using RCS and iMessage instead of the usual SMS, making its attacks more effective.
To make matters worse, Darcula allows its users to auto-generate phishing kits for almost any conceivable brand, convert credit cards to virtual cards, and with the help of Generative Artificial Intelligence (GenAI), they can create phishing messages in almost any language and on almost any topic.
Darcula’s operators seem to be Chinese in origin, since most communication is done in closed Telegram groups and in Chinese language. The researchers also observed SIM farms and hardware setups which allow the operators to offer mass text messages and credit card processing through terminals.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
A September 2024 report from security researchers Zimperium argued four in five (82%) of all phishing sites today target mobile devices, since they are generally weaker and more often unmanaged compared to desktop and laptop computers.
Defending against phishing, however, hasn’t changed much. It still revolves around common sense, being skeptical of all incoming messages, especially those with a sense of urgency, or unexpected attachments.
Clicking on links in emails and SMS messages, particularly those hidden behind a placeholder or a URL shortener, is also risky.
Via BleepingComputer
You might also like
Around 600 threat actors are using Darcula, experts warn They have managed to steal more than 800,000 credit card details in less than a year Mobile devices are prime targets for phishing nowadays Darcula, an infamous Phishing-as-a-Service (PhaaS) kit, has helped hundreds of its users steal almost a million credit…
Recent Posts
- This dastardly phishing attack has stolen nearly a million credit cards – here’s how to stay safe
- Google’s iOS app will use AI to simplify jargon
- Pro-Ject Flatten It Review: Finally, a Way to Fix Warped Records
- Xbox is selling a lot of games on PlayStation
- Grand Theft Auto 6 trailer 2 live: analysis of the new GTA 6 trailer and all the latest news
Archives
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010