Home -
Original -
Main body -

WikiFX Express

Exness
EC Markets
TMGM
XM
FXTM
FOREX.com
AvaTrade
FXCM
IC Markets Global
ACCM

Who Are the Cybercriminals Behind the Darcula Phishing Network?

WikiFX
| 2025-05-07 14:41

Abstract:Norwegian researchers uncover Darcula, a phishing-as-a-service operation with 884,000 stolen cards, linking scammers to luxury goods and global crime rings.

Who Are the Cybercriminals Behind Darcula Phishing.jpg

A team of Norwegian cybersecurity specialists has revealed a sprawling cybercrime syndicate, exposing the sophisticated fraud tactics employed by the scammers orchestrating it. Their findings have unveiled a highly structured phishing-as-a-service scheme called Darcula, which has ensnared countless victims worldwide.

Operating out of Oslo, the Mnemonic research group launched their probe after detecting a spike in fraudulent delivery-related messages targeting global users in 2023. By engaging with one of these deceptive links, the researchers uncovered a platform engineered to equip cybercriminals with tools for executing widespread phishing campaigns. Known as Darcula, this platform, active since at least 2023, grants access to over 20,000 domains and 200 phishing templates mimicking prominent brands like postal services, tax authorities, telecom companies, and airlines.

Though prevalent on the dark web, Darcula evaded detection until Mnemonic‘s ethical hackers penetrated its covert admin hub. Their report describes this hub as the nerve center of the operation, displaying live updates of victims’ personal data—such as credit card details, names, and addresses—as they were entered. This formed part of a vast network where phishing links were clicked over 13 million times, resulting in the theft of 884,000 credit cards by approximately 600 fraudsters.

Phishing.jpg

Through reverse engineering, Mnemonic identified a critical element of the scheme: a toolkit dubbed ‘Magic Cat.’ This tool allowed scammers to track stolen credit card information in real time and engage with victims to extract additional data, such as PINs. Magic Cat offered features like ready-to-use templates for impersonating numerous global brands, making it a user-friendly resource for fraudsters worldwide.

As their investigation deepened, Mnemonic traced the Darcula network to Chinese cybercriminals, identifying the full name, phone number, and city of a key figure behind the operation. The Norwegian Broadcasting Corporation (NRK) joined the effort, uncovering over 40,000 chat exchanges among the scammers. These conversations revealed the criminals bragging about their opulent lifestyles, fueled by illicit gains.

One fraudster showcased a ring valued at over £21,000, while another flaunted luxury Valentino footwear. Receipts showed some had spent up to £14,000 on personal purchases, with images depicting sports cars and high-end dining experiences, all financed through stolen credit card data.

Despite presenting the hackers with evidence of their crimes, Mnemonic and NRK encountered defiance and subtle threats from the perpetrators.

The investigation confirmed that the Darcula network and its Magic Cat toolkit remain active, with ongoing enhancements making the phishing operations increasingly effective.

Mnemonics report emphasized that their original aim was to investigate active phishing campaigns, but their work uncovered a far larger and more intricate web of fraudsters operating a robust ecosystem designed to exploit globally recognized brands. They identified hundreds of thousands of victims and thousands of licenses sold for Magic Cat, highlighting a rising trend in cybercrime.

This investigation has not only illuminated the scope of this criminal enterprise but also offered a vital glimpse into the lucrative realm of cyber fraud, where perpetrators live extravagantly at the expense of unsuspecting victims. Despite the researchers‘ efforts, Darcula and its tools continue to flourish, emphasizing the persistent danger posed by cybercriminals lurking in the dark web’s shadows.

Footer.jpg
Breaking NewsMarket NewsScam AlertInvestment ScamFraud Alert

Read more

Risky Choice? What Traders Should Know About Bold Prime

Risk exists everywhere — even well-known brokers are not exceptions. But they often don’t talk about the risks. Instead, they highlight their strengths and try to attract customers while hiding the potential downsides. However, in this article, you’ll learn about the risks involved with Bold Prime.

Original 2025-07-15 19:58

From Novice to Pro: Why Investors Trust Land Prime?

If you're passionate about forex trading and ready to begin your journey as a trader, this article is worth exploring. It highlights the key features that Land Prime offers to both traders and investors.

Original 2025-07-15 18:13

Five Positive Signs That Make BCR Reliable Broker

Thinking of investing? Exploring Brokers and Have you come across BCR Forex Broker but feel confused? Is it a great choice or a bad decision? Hold on . Check out the article and know why this broker could be a trustworthy choice for you.

Original 2025-07-15 17:58

How Fake News Sites Are Fueling a Global Investment Scam Epidemic

A surge in sophisticated investment scams has been uncovered, exploiting fake news websites that mimic globally trusted media outlets such as CNN, the BBC, and CNBC. According to a July 2025 report by cybersecurity firm CTM360, more than 17,000 fraudulent websites have been detected, designed to mislead users and funnel them into elaborate financial traps.

Original 2025-07-15 16:04

WikiFX Express

Exness
EC Markets
TMGM
XM
FXTM
FOREX.com
AvaTrade
FXCM
IC Markets Global
ACCM

WikiFX Broker

FXTM

FXTM

Regulated
Exness

Exness

Regulated
DBG Markets

DBG Markets

Regulated
XM

XM

Regulated
EC Markets

EC Markets

Regulated
CPT Markets

CPT Markets

Regulated
FXTM

FXTM

Regulated
Exness

Exness

Regulated
DBG Markets

DBG Markets

Regulated
XM

XM

Regulated
EC Markets

EC Markets

Regulated
CPT Markets

CPT Markets

Regulated

WikiFX Broker

FXTM

FXTM

Regulated
Exness

Exness

Regulated
DBG Markets

DBG Markets

Regulated
XM

XM

Regulated
EC Markets

EC Markets

Regulated
CPT Markets

CPT Markets

Regulated
FXTM

FXTM

Regulated
Exness

Exness

Regulated
DBG Markets

DBG Markets

Regulated
XM

XM

Regulated
EC Markets

EC Markets

Regulated
CPT Markets

CPT Markets

Regulated

Latest News

Top Wall Street analysts are upbeat about these dividend-paying stocks

WikiFX
2025-07-13 12:44

Singapore's economy grows 4.3% in second quarter, beating expectations

WikiFX
2025-07-14 01:10

What WikiFX Found When It Looked Into Emar Markets

WikiFX
2025-07-14 15:55

MT4 vs MT5 Which Forex Trading Platform Fits Your Needs in 2025?

WikiFX
2025-07-14 15:25

Stock futures slide on more Trump tariff letters, but are off worst levels of session: Live updates

WikiFX
2025-07-13 23:03

Short or Long Term: Which to Choose for Double-Digit Returns from Gold Investments?

WikiFX
2025-07-14 17:58

Gold Soars Above $3,350 as XAU/USD Rallies on Trade Tensions

WikiFX
2025-07-14 16:18

Asia-Pacific markets trade mixed as investors assess Trump's latest tariff threats; bitcoin hits new highs

WikiFX
2025-07-14 00:47

What is Forex Trading Simulator?

WikiFX
2025-07-14 16:48

Switzerland tourism boosted as women's soccer continues record-breaking rise

WikiFX
2025-07-14 15:11

Rate Calc

USD
CNY
Current Rate: 0

Amount

USD

Available

CNY
Calculate

You may also like

Meiji Yasuda

Meiji Yasuda

Ardu Prime

Ardu Prime

Cathay Securities

Cathay Securities

Gdmcgjpme

Gdmcgjpme

WOHLSTAND

WOHLSTAND

Caxton

Caxton

Netotrade

Netotrade

Trustbanc

Trustbanc

Smart Capitals Global

Smart Capitals Global

Plus5 Trade

Plus5 Trade