• News/
  • https://www.bleepingcomputer.com/news/security/new-darcula-phishing-service-targets-iphone-users-via-imessage/

New Darcula phishing service targets iPhone users via iMessage

BleepingComputer
·
Bill Toulas
·
Published Mar 27, 2024
·
Updated

A new phishing-as-a-service (PhaaS) named ‘Darcula’ uses 20,000 domains to spoof brands and steal credentials from Android and iPhone users in more than 100 countries. Darcula has been used against various services and organizations, from postal, financial, government, taxation departments, to telcos, airlines, utility, offering fraudsters over 200 templates to choose from. One thing that makes the service stand out is that it approaches the targets using the Rich Communication Services (RCS) protocol for Google Messages and iMessage instead of SMS for sending phishing messages. Darcula was first documented last summer by security researcher Oshri Kalfon but Netcraft analysts report that the platform has been becoming more popular on the cybercrime space, and was recently used in several high-profile cases. Unlike traditional phishing methods, Darcula employs modern technologies like JavaScript, React, Docker, and Harbor, enabling continuous updates and new feature additions without clients needing to reinstall the phishing kits. The phishing kit offers 200 phishing templates that impersonate brands and organizations in more than 100 countries. The landing pages are high-quality and use the correct local language, logos, and content. The fraudsters select a brand to impersonate and run a setup script that installs the corresponding phishing site and its management dashboard directly into a Docker environment. The system uses the open-source container registry Harbor to host ...

Read full article

Affected Software

2 affected components
Google Messages
Apple iMessage

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new phishing service called 'Darcula' that targets iPhone and Android users via iMessage.

2

What security implications are discussed in this article?

The article highlights the risks of credential theft and the widespread reach of the Darcula phishing service across over 100 countries.

3

What products or software are affected by the Darcula phishing service?

The Darcula phishing service targets both Apple iMessage and Google Messages.

4

How many domains does the Darcula phishing service use to spoof brands?

The Darcula service uses approximately 20,000 domains to impersonate various brands.

5

Who are the primary targets of the Darcula phishing attacks?

The primary targets of Darcula phishing attacks are iPhone and Android users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203