Article Details

Scrape Timestamp (UTC): 2025-04-24 11:28:26.481

Source: https://thehackernews.com/2025/04/darcula-adds-genai-to-phishing-toolkit.html

Original Article Text

Click to Toggle View

Darcula Adds GenAI to Phishing Toolkit, Lowering the Barrier for Cybercriminals. The threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have released new updates to their cybercrime suite with generative artificial intelligence (GenAI) capabilities. "This addition lowers the technical barrier for creating phishing pages, enabling less tech-savvy criminals to deploy customized scams in minutes," Netcraft said in a new report shared with The Hacker News. "The new AI-assisted features amplify Darcula's threat potential by simplifying the process to build tailored phishing pages with multi-language support and form generation — all without any programming knowledge." Darcula was first documented by the cybersecurity company in March 2024 as a toolkit that leveraged Apple iMessage and RCS to send smishing messages to users that trick recipients into clicking on bogus links under the guise of postal services like USPS. Earlier this year, the operators of Darcula PhaaS began testing a major update that enabled customers to clone any brand's legitimate website and create a phishing version. The phishing kit, per PRODAFT, is the work of a threat actor codenamed LARVA-246, and is advertised for sale via a Telegram channel named xxhcvv / darcula_channel. It shares identical features and templates with another PhaaS referred to as Lucid. Darcula, Lucid, and Lighthouse are assessed to be part of a loosely connected cybercrime ecosystem flourishing out of China, enabling threat actors to pull off various financially motivated scams such as those perpetrated by an activity cluster dubbed Smishing Triad. "Darcula is one of several communities under the loosely affiliated Smishing-Triad, known for mass-targeting individuals globally via SMS-based phishing (smishing) attacks," Netcraft said. What makes Darcula compelling is that it makes it possible for threat actors with little to no technical expertise to easily craft phishing pages and conduct campaigns at scale. The latest improvement to the phishing kit, announced on April 23, 2025, takes the form of GenAI integration that facilitates phishing form generation in various languages, form field customisation, and translation of phishing forms into local languages. The cybersecurity company said it has taken down more than 25,000 Darcula pages, blocked nearly 31,000 IP addresses, and flagged over 90,000 phishing domains since March 2024. "This kind of flexibility means a novice attacker can now build and deploy a customized phishing site in minutes," security researcher Harry Everett said.

Daily Brief Summary

CYBERCRIME // Darcula Phishing Tool Integrates GenAI, Expands Cybercrime Reach

Darcula, a phishing-as-a-service platform, has been updated to include generative artificial intelligence (GenAI) features, significantly reducing the technical knowledge required to create phishing campaigns.

The GenAI capabilities enable the rapid development of customized phishing pages with multi-language support and automatic form generation, without needing programming skills.

Initially identified in March 2024, Darcula has evolved from using smishing techniques with Apple iMessage and RCS to more sophisticated phishing site generation mimicking legitimate brands.

The platform is operated by a threat actor known as LARVA-246 and is part of a broader cybercrime ecosystem linked to China, facilitating a variety of financial scams.

The latest GenAI update was announced on April 23, 2025, enhancing the ability for attackers to generate phishing forms in different languages and customize form fields.

Since its documentation, over 25,000 Darcula-linked phishing pages have been taken down by cybersecurity efforts, along with the blocking of nearly 31,000 IP addresses and flagging of over 90,000 domains.

The ease of use introduced by GenAI in Darcula allows even novice cybercriminals to set up and deploy tailored phishing sites within minutes, underscoring an escalation in the tool's threat level.