logo
884,000 Credit Cards Stolen With 13 Million Clicks By A Magic Cat

884,000 Credit Cards Stolen With 13 Million Clicks By A Magic Cat

Forbes06-05-2025

Darcula steals 884,000 credit cards — here's how. getty
Two threats have been dominating cybersecurity news headlines recently: phishing and 2FA-bypass attacks. The former is often a precursor to the latter, of course. But what if there were a campaign that combined the two in one deadly attack? Welcome to the distinctly dangerous world of Darcula and the Magic Cat, which has proven that nearly 900,000 credit cards can be stolen with enough clicks if you do. Forbes Confirmed — 19 Billion Compromised Passwords Published Online By Davey Winder
According to cybersecurity researchers Harrison Sand and Erlend Leiknes, working with Mnemonic, cybercriminals with the Darcula group have been using custom-made malware called Magic Cat to target consumers, mainly in North America and Europe, and steal credit card data. The Mnemonic report, took a deep technical dive into the SMS text message phishing-as-a-service attacks executed by the Darcula group since December 2023. An investigation into the mastermind behind the Magic Cat attacks revealed a phishing operation with victims spanning 32 countries, involving 13 million clicks, and ending up with a not-so-shabby payload of some 884,000 stolen credit cards. I advise you read both to get a full understanding of the threat and the dangerous criminals behind it.
Having successfully created some code that enabled them to read the messages that the attackers were seeing, the security researchers said they were shocked at what this was. 'Flying by our screen was a stream of names, addresses, and credit cards, a real-time feed of hundreds of victims being phished.' Eventually, the researchers were able to access the Telegram group used by Darcula members and download the Magic Cat malware itself.
It turned out to be rather easy to get the software configured. 'All we had to do was copy and paste that one simple command,' Sand and Leiknes said, 'and the phishing software was basically ready to go.'Once, that is, they had hacked their way into activating the unlicensed copy they now had. It is this ease of use that attracts so many attackers to such phishing kits, but it's not what concerns some security experts the most about Magic Cat. Forbes Google Says Critical Android 'No User Interaction' Attacks Underway By Davey Winder
Javvad Malik, the lead security awareness advocate at KnowBe4, acknowledged the sophistication and scale of the credit card phishing cyberattacks, but said that 'what is particularly alarming is Darcula's ability to circumvent multi-factor authentication through real-time session hijacking.' Addressing this 2FA cookie-stealing threat, Malik said, requires a coordinated response from the financial institution, cybersecurity firm and law enforcement agencies triad. The Darcula campaign and Magic cat malware, Malik concluded, 'serves as a reminder that constant vigilance and adaptive security measures are essential.'

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Key moments from the fourth week of Sean 'Diddy' Combs' sex trafficking trial
Key moments from the fourth week of Sean 'Diddy' Combs' sex trafficking trial

Associated Press

time23 minutes ago

  • Associated Press

Key moments from the fourth week of Sean 'Diddy' Combs' sex trafficking trial

NEW YORK (AP) — The fourth week of Sean 'Diddy' Combs ' sex trafficking trial featured testimony from the second of two ex-girlfriends who are crucial witnesses in the government's quest to prove sex trafficking and racketeering conspiracy charges against the hip-hop mogul. Combs, the founder of Bad Boy Records, has pleaded not guilty in the trial, which resumes Monday. Here are key moments from the past week: Hotel worker says Combs sought video of Cassie beating Fearing career ruin, Combs delivered $100,000 in cash to a security guard for a Los Angeles hotel in return for assurances that he was given the only security footage of Combs' 2016 attack on then-girlfriend Casandra 'Cassie' Ventura, the security guard testified. Eddy Garcia, 33, recounted how the deal came to be, saying he first heard from a fast talking, stuttering and 'very nervous' Combs on a phone call seeking to obtain the video of him kicking and dragging Cassie from the hotel's elevator bank into a hallway because 'if this got out it could ruin him.' Days later, Garcia said, he was the nervous one when he was greeted in an office building by a smiling Combs who called him 'Eddy, my angel' before Garcia turned over a USB drive containing the security footage. Combs then made him sign a nondisclosure agreement promising it was the only copy of the video and that Garcia would never speak of it, he said. Then, Combs, with a bodyguard at his side, fed stacks of cash from a brown bag into a rectangular money counter machine until it reached $100,000, Garcia said. He said he pocketed $30,000 and gave $50,000 to his boss and $20,000 to another hotel security guard. Garcia testified under immunity. A recording of the hotel attack on Cassie aired on CNN last year and security footage along with clips of the security tape recorded by a guard on his personal phone so he could show it to his wife have been shown repeatedly during the trial. Judge threatens Combs with trial expulsion Minutes after a prosecutor complained that Combs was seen 'nodding furiously' as his lawyer cross examined a witness on Thursday, Judge Arun Subramanian took a look himself and said he saw Combs 'nodding vigorously and looking at the jury' and doing the same later when the lawyers and the judge were having a sidebar discussion. Assistant U.S. Attorney Maurene Comey said prosecutors were concerned because the gestures amounted to 'testifying by nodding affirmatively' while his lawyer asked questions. During a lunch break, defense lawyer Marc Agnifilo promised to speak with Combs and ensure it wouldn't happen again after the judge told him it was 'absolutely unacceptable.' The judge sternly responded: 'If it happens again, if it happens even once, I will hear an application from the government to give a curative instruction to the jury, which you do not want. Or I will consider taking further measures, which could result in the exclusion of your client from the courtroom.' Mia says she was 'brainwashed' to send Combs loving texts after rape A former Combs personal assistant who testified under the pseudonym 'Mia' told jurors that Combs had sexually assaulted her multiple times over her eight-year career, though the attacks were 'random, sporadic, so oddly spaced out' so that she thought each was the last. She said he first molested her and forcibly kissed her at his 40th birthday party before raping her months later in a guest room at his Los Angeles home. On cross examination, defense lawyer Brian Steel's suggested that she fabricated her claims to cash in on 'the #MeToo money grab against Sean Combs.' Steel confronted her with loving texts she sent Combs long after her employment ended and asked how she could tell him, as she did in a 2019 text, that she had imagined Combs rescuing her from a nightmare in which she was trapped in an elevator with R. Kelly, the singer who has since been convicted of sex trafficking. 'I was still brainwashed,' Mia explained. Defense has success with questioning of Cassie's friend The defense had one of its most successful moments of the trial when attorney Nicole Westmoreland cast doubt on the credibility of a graphic designer who says Combs once dangled her from the balcony of a 17th-floor apartment in Los Angeles. Bryana 'Bana' Bongolan, a friend of Cassie who is suing Combs, had taken a cellphone image of a softball-size welt on her leg that she said occurred when Combs held her over the balcony for 10 to 15 seconds and then threw her into furniture. After it was shown to the jury, Westmoreland showed the jury cellphone metadata revealing that the photograph was taken while Combs was on tour in September 2016, staying at a Manhattan hotel. 'You agree that one person can't be in two places at the same time?' Westmoreland asked. 'In, like, theory, yeah,' Bongolan responded. 'You're not sure?' Westmoreland asked. 'Hard to answer that one,' she said. Later, Bongolan said she did not recall the exact date, but she had no doubt the balcony episode happened. Woman recalls sex performances during three years as a Combs' girlfriend A woman testifying under the pseudonym 'Jane' fought through tears and sobs to recount frequent sexual performances she participated in with male sex workers to please Combs and keep their three-year relationship alive until his September arrest. Jane's testimony, which is likely to continue deep into next week, is identical in many ways to the four-day testimony in the trial's first week by Cassie. Jane said she never wanted to have sex with other men but did it to please Combs because she loved him. Cassie described having hundreds of drug-fueled sexual performances known as 'freak-offs' in which she had sex with male sex workers for days at a time while Combs watched, sometimes directed the activity, and pleasured himself. Jane described having nearly the same experiences from 2021 until last August, though she called them 'hotel nights.' She said her relationship with Combs began with romance but later became reliant upon the sexual performances, especially after Combs began paying rent for her apartment. Defense attorneys have insisted that Jane and Combs only engaged in consensual sex and that Jane's protests to Combs in text messages were fueled by jealousy.

Milwaukee homicide near 95th and Silver Spring; Elbert Milan sentenced
Milwaukee homicide near 95th and Silver Spring; Elbert Milan sentenced

Yahoo

timean hour ago

  • Yahoo

Milwaukee homicide near 95th and Silver Spring; Elbert Milan sentenced

The Brief Elbert Milan Jr. was sentenced on Friday, June 6 to 35 years in prison in connection with a fatal shooting in Milwaukee in June 2023. The shooting happened near 95th and Silver Spring. A jury found Milan guilty in April of first-degree reckless homicide. MILWAUKEE - A Milwaukee County judge sentenced Elbert Milan Jr. on Friday, June 6 to 35 years in prison and an additional ten years of extended supervision in connection with with a fatal shooting near 95th and Silver Spring in June 2023. A jury found Milan guilty of first-degree reckless homicide in April. What we know According to the criminal complaint, Milwaukee police were dispatched to the area of 95th and Silver Spring for a shooting on Thursday, June 8, 2023. A detective on the scene spotted the victim, a 35-year-old man, with gunshot wounds outside a car. Lifesaving efforts were attempted, but the victim was pronounced deceased on the scene. Investigators noted the victim's address was less than a quarter mile from the shooting scene. FREE DOWNLOAD: Get breaking news alerts in the FOX LOCAL Mobile app for iOS or Android Officers learned a suspect was seen running north on N. 95th Street. As police tried to locate that person, they were informed a person had walked into St. Joseph's Hospital with a gunshot wound -- and that person was the defendant, Elbert Milan. The complaint says the "defendant also matched the description of the homicide suspect that officers had received." When police spoke with Milan, he indicated he was in the back of a car and "asleep when he was woken up by an array of gunfire," the complaint says. According to the criminal complaint, a woman spoke with a detective and indicated she and friends "were all at McDonald's when an employee of McDonald's, later identified as offered to sell them crack/cocaine and he gave them samples of what he was selling." For the week leading up to the shooting, the woman indicated they had "been buying crack from the defendant. All of the purchases have happened either at the McDonald's or near the defendant's house," the complaint says. On July 3, 2023, a detective received tower data from T-Mobile. An officer analyzed that data on Nov. 22, 2023 -- and "determined that the defendant's phone was in the area of both the defendant's residence and the homicide scene between 2:07 p.m. and 2:32 p.m." on June 8, 2023. Additionally, the data revealed the defendant was in the area of St. Joseph's Hospital between 2:56 p.m. and 3:17 p.m. on June 8, 2023. SIGN UP TODAY: Get daily headlines, breaking news emails from FOX6 News The complaint says on Oct. 28, 2023, a detective received a DNA report from the Wisconsin State Crime Lab. The report contained results regarding DNA swabs that were submitted to the crime lab from areas in and around the vehicle that was at the scene of the homicide on June 8, 2023. The complaint says "swabs that were obtained from the outside of the front passenger door were single source male profiles. This profile belongs to Elbert Milan," the defendant. The Source The information in this post was provided by Wisconsin Circuit Court Access as well as the criminal complaint associated with this case.

Kilmar Abrego Garcia Returned To U.S. & Facing Criminal Charges - Anderson Cooper 360 - Podcast on CNN Audio
Kilmar Abrego Garcia Returned To U.S. & Facing Criminal Charges - Anderson Cooper 360 - Podcast on CNN Audio

CNN

time2 hours ago

  • CNN

Kilmar Abrego Garcia Returned To U.S. & Facing Criminal Charges - Anderson Cooper 360 - Podcast on CNN Audio

Kilmar Abrego Garcia Returned To U.S. & Facing Criminal Charges Anderson Cooper 360 47 mins The man mistakenly deported to an El Salvadorian prison has been returned to the United States and indicted. We are now learning the prosecutor in charge has resigned over it. Plus, what Elon Musk and Donald Trump are saying now about their breakup. Also, a look at how Musk's insinuation about the President and sex offender Jeffrey Epstein is landing with the MAGA faithful.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store