Trending Topics

Darcula is after your digital lifeblood, and garlic won’t save you
With apologies to Bauhaus, Bela Lugosi isn’t the only one who’s undead, undead, undead: the phishing threat also walks among us. Not only has there been a surge in phishing attack incident reports, but according to newly published research, the third-coming of ‘Darcula’ could soon sink its social engineering fangs into pretty much any brand you can think of.
This notorious Phishing-as-a-Service platform is coming for the lifeblood of your organisation, data, and neither garlic nor a crucifix will help you.
What you need to know about Darcula
Netcraft security researchers have been analysing the Darcula phishing suite – Netcraft’s description not mine, I should add, as I’d have called it a grubby motel room – since March 2024.
In that time more than 90,000 new phishing domains have been detected and blocked by this security outfit alone, encompassing over 30,000 IP addresses and responsible for in excess of 20,000 fraudulent websites.
Now, in what has been described as a “significant shift in criminal capabilities,” the criminal coders behind the platform are expected to launch the third version in a matter of days. Darcula v3 will, we are warned, reduce “the barrier to entry for bad actors to target any brand with complex, customizable phishing campaigns”.
“This Cybercrime-as-a-Service model offers ready-made phishing tools and support and is available on underground forums and Telegram marketplaces,” states the LevelBlue 2025 Threats report. “The ease with which these tools can be accessed means that even individuals with minimal technical expertise can use PhaaS platforms to carry out advanced phishing attacks.”
Darcula 3 gets worse
That’s something nobody needs to hear, and it gets worse: the use of ‘Headless Chrome’ alongside browser automation tools makes this a wannabe hacker’s wet dream. “Even non-technical criminals,” Netcraft said, can “quickly and easily clone any brand’s legitimate website and create a phishing version.”
The “worse” bit was hidden in there; did you spot it? Probably not, because that’s the point of Headless Chrome. According to Chrome developers themselves, using Chrome’s headless mode means that you “can run the browser in an unattended environment, without any visible UI”.
So, to recap: all the wannabe hacker needs to do is throw a URL for any brand into the Darcula kit which will then automatically generate the templates that are needed in order to execute the attack. Everything, in a matter of minutes, including a perfect clone of the legitimate branded site including all CSS, HTML, Javascript, everything.
This thing is so sophisticated it comes with the type of campaign metrics dashboard you might think of as used by marketing outfits, as well as the more obvious crime stuff such as automated card and data theft, fake password reset pages, 2FA prompts. And the list goes on.
“As in all scam and fraud cases, consumers can protect themselves by being wary of messages and links sent from unrecognized senders,” Netcraft advised. Those requiring “urgent action should continue to be treated with significant skepticism”.
Which is cold comfort when a headless digital vampire is hunting you down.
