Magic Cat
Magic Cat is software used by the phishing-as-a-service provider Darcula to enable low-skill scammers to run phishing campaigns. According to the provided reporting, Darcula used Magic Cat to impersonate trusted organizations including the USPS, IRS, and E-ZPass in large-scale phishing text-message operations. Google Threat Intelligence Group assessed that Darcula was responsible for 80 percent of all phishing text messages during a peak period earlier in the year. The campaigns were reported to have resulted in the theft of nearly 900,000 credit card numbers worldwide, including 40,000 from victims in the United States. High-confidence associations in the content link Magic Cat directly to Darcula’s phishing infrastructure and fraud operations; no additional technical indicators or platform-specific implementation details are provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group leveraged their Magic Cat software to allow scammers with limited technical skill to impersonate trusted organizations like the USPS, IRS, and E-ZPass.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service software kit used by the Darcula operation to enable low-skill scammers to impersonate trusted organizations and steal payment card data.
SMS scamware operation used for large-scale payment card theft (credit card harvesting) supported by phone farms and cash-out infrastructure.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.