GenAI-Powered Darcula: How AI Is Making Sophisticated Phishing Attacks Accessible to All Cybercriminals


# Darcula Phishing Platform Adds AI Capabilities, Lowering Technical Barriers for Cybercriminals

Threat actors behind the Darcula phishing-as-a-service (PhaaS) platform have integrated generative artificial intelligence (GenAI) capabilities into their cybercrime toolkit, significantly reducing technical barriers for would-be scammers.

According to a recent Netcraft report, “The new AI-assisted features amplify Darcula’s threat potential by simplifying the process to build tailored phishing pages with multi-language support and form generation — all without any programming knowledge.”

First documented in March 2024, Darcula initially specialized in smishing attacks via Apple iMessage and RCS, impersonating postal services like USPS. The platform has since evolved to allow customers to clone legitimate websites and create convincing phishing versions.

Security researchers attribute Darcula to a threat actor codenamed LARVA-246, who markets the service through a Telegram channel named xxhcvv / darcula_channel. The platform shares features with another PhaaS called Lucid, with both believed to be part of a Chinese cybercrime ecosystem alongside a service called Lighthouse.

The April 2024 GenAI update enables:
– Automated phishing form generation in multiple languages
– Form field customization
– Translation capabilities for localized attacks

“This kind of flexibility means a novice attacker can now build and deploy a customized phishing site in minutes,” explained security researcher Harry Everett.

Since March 2024, Netcraft has taken down over 25,000 Darcula pages, blocked nearly 31,000 IP addresses, and flagged more than 90,000 phishing domains associated with this growing threat.

Share This Article