A new phishing-as-a-service (PhaaS) named ‘Darcula’ uses 20,000 domains to spoof brands and steal credentials from Android and iPhone users in more than 100 countries. Darcula has been used against various services and organizations, from postal, financial, government, taxation departments, to telcos, airlines, utility, offering fraudsters over 200 templates to choose from. One thing that makes the service stand out is that it approaches the targets using the Rich Communication Services (RCS) protocol for Google Messages and iMessage instead of SMS for sending phishing messages. Darcula was first documented last summer by security researcher Oshri Kalfon but Netcraft analysts report that the platform has been becoming more popular on the cybercrime space, and was recently used in several high-profile cases. Unlike traditional phishing methods, Darcula employs modern technologies like JavaScript, React, Docker, and Harbor, enabling continuous updates and new feature additions without clients needing to reinstall the phishing kits. The phishing kit offers 200 phishing templates that impersonate brands and organizations in more than 100 countries. The landing pages are high-quality and use the correct local language, logos, and content. The fraudsters select a brand to impersonate and run a setup script that installs the corresponding phishing site and its management dashboard directly into a Docker environment. The system uses the open-source container registry Harbor to host ...
New Darcula phishing service targets iPhone users via iMessage
BleepingComputer
·Bill Toulas
·Published Mar 27, 2024
·Updated
Affected Software
2 affected components
Google Messages
Apple iMessage
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new phishing service called 'Darcula' that targets iPhone and Android users via iMessage.
2
What security implications are discussed in this article?
The article highlights the risks of credential theft and the widespread reach of the Darcula phishing service across over 100 countries.
3
What products or software are affected by the Darcula phishing service?
The Darcula phishing service targets both Apple iMessage and Google Messages.
4
How many domains does the Darcula phishing service use to spoof brands?
The Darcula service uses approximately 20,000 domains to impersonate various brands.
5
Who are the primary targets of the Darcula phishing attacks?
The primary targets of Darcula phishing attacks are iPhone and Android users.