OTHER

New Scheme Emerges After Major SMS Scam Revelation

If you’ve encountered scam messages concerning unpaid tolls or missing packages in the U.S. and elsewhere, you might be a target of a widespread fraudulent scheme.

What seems like a simple scam at first glance has proven to be highly effective. Scammers send spam texts mimicking genuine notifications from trusted organizations—such as postal services and local government alerts—to trick victims into clicking on links that lead to phishing sites. Victims may inadvertently share their credit card details, which are then exploited for fraudulent activities.

In the first seven months of 2024, roughly 884,000 credit card numbers have been compromised through this scheme, allowing criminals to take advantage of victims’ accounts. Experts report that many individuals have incurred significant financial losses due to this.

Nevertheless, major lapses in operational security ultimately disclosed the identity of the individual behind the scam software known as Magic Cat, who is referred to as Darcula.

Image of a profile picture of a notable scammer, featuring a fluffy white cat on a couch.
Image Credits:via Mnemonic

Recent information from the Oslo-based security firm Mnemonic and Norwegian media indicates that the charming cat in Darcula’s profile actually belongs to a 24-year-old Chinese national named Yucheng C.

Researchers suggest that Yucheng C. is the brains behind Magic Cat, which has been employed by various clients to launch their own SMS scam operations against unsuspecting targets.

After Yucheng C.’s identity was made public, Darcula disappeared from online platforms, ceasing his fraudulent activities and leaving his clients bewildered. However, a new scam has quickly emerged in his absence.

New alerts have been raised concerning a fraudulent operation called Magic Mouse, which surfaced following the termination of Magic Cat.

Harrison Sand, an offensive security consultant at Mnemonic, informed TechCrunch that Magic Mouse has gained considerable momentum since the discontinuation of Darcula’s Magic Cat. He intends to share new findings at the Def Con security conference in Las Vegas this Friday.

Sand cautioned about Magic Mouse’s growing capacity to unlawfully acquire credit card information on a large scale.

During their investigation, Mnemonic uncovered images shared in a Telegram channel run by Darcula, showing rows of credit card payment terminals and videos highlighting multiple phones employed to automate messaging to victims.

The scammers leverage the stolen card details across various mobile wallets, executing payment fraud and laundering the proceeds through multiple bank accounts. Many devices were discovered preloaded with mobile wallets containing stolen card data, ready for rapid deployment.

Sand reported that Magic Mouse is currently responsible for the theft of at least 650,000 credit card numbers each month.

While Magic Mouse appears to be a completely new operation led by different individuals and seems unrelated to Darcula, its swift rise is linked to operators who used the same phishing kits responsible for Magic Cat’s success. These kits include various phishing sites that Magic Cat utilized to mimic legitimate pages of major tech companies, well-established consumer services, and delivery organizations, deceiving victims into revealing sensitive credit card information.

Despite the severe threats posed by both Magic Cat and the newer Magic Mouse to consumer financial security, Sand remarked to TechCrunch that law enforcement seems to be focusing on individual fraud cases rather than the larger criminal networks behind these scams.

Sand emphasized that technology companies and financial institutions bear the primary responsibility for combating these scams and making it increasingly difficult for fraudsters to exploit stolen card information.

For anyone who receives suspicious text messages, the most prudent action may be to ignore unsolicited communications.