Netcraft details Darcula, a Chinese-language Phishing-as-a-Service platform that operates across 100+ countries with more than 20,000 phishing domains and updates its templates in place to evade detection. It delivers smishing campaigns via iMessage and RCS to bypass SMS filters and targets USPS and other postal services worldwide, leveraging Docker/Harbor for hosting and a cat-themed anti-detection approach. #darcula #smishing #RCS #iMessage #USPS
Keypoints
- Darcula is a Phishing-as-a-Service (PhaaS) platform offering easy deployment of phishing sites with hundreds of templates for many brands.
- The platform distributes phishing URLs via iMessage and RCS to bypass SMS filters and reach users in 100+ countries, with USPS and other postal services highlighted.
- Phishing sites spoof trusted brands and use purpose-registered domains with common TLDs like .top and .com.
- Darcula hosts phishing pages using Harbor (an open-source container registry) and Docker images, enabling in-place updates without reinstalling the kit.
- Anti-detection features include masquerading techniques and an anti-monitoring mechanism that redirects bots to unrelated searches (cat breeds).
MITRE Techniques
- [T1566.003] Spearphishing via Service – PhaaS platforms like darcula provide easy deployment of phishing campaigns; ‘the darcula platform claims to support around 200 phishing templates, covering a large range of brands.’
- [T1566.002] Spearphishing Link – Phishing campaigns use URLs delivered through iMessage and RCS; ‘Those operating sites using darcula frequently distribute their URLs via RCS and iMessage.’
- [T1036] Masquerading – The kit hides the attack by changing how content is accessed (e.g., using /track path to disguise the location); ‘malicious content available through a specific path (i.e. example.com/track), rather than the front page (example.com) to disguise the attack’s location.’
- [T1583] Acquire Infrastructure – Infrastructure hosted on Harbor to serve Docker-based phishing sites; ‘uses the open-source container registry Harbor to host Docker images of phishing websites written in React.’
- [T1562] Impair Defenses – Anti-monitoring and bot-detection evasion techniques, including redirecting suspected bots to cat-breed Google searches; ‘anti-monitoring mechanism would redirect visitors that are believed to be bots … to Google searches for various cat breeds.’
Indicators of Compromise
- [Domain] Infrastructure hosting – magic-cat.net, cloudflare.com – used to host phishing pages and conceal server IPs
- [Domain] Targeted branding domains and URLs – example.com/track and related brand domains (used to disguise location)
- [Top-Level Domain] TLD usage – .top, .com – commonly used for darcula campaigns
Read more: https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services/