From SMS to Server: The First Click
Sand and Leiknes received a text message pretending to be the Norwegian Postal Office. News coverage told people to delete the message. They clicked the link instead. The phishing site loaded on their phone but returned a “not found” page when loaded in Burp Suite. The site checked two things: the user agent and the source IP. It required a mobile network IP, likely to block automated scanners. By matching both, they accessed the real phishing page and saw websocket traffic flowing through socket.io.
Real-Time Phishing: The Admin Room
The site used socket.io with encrypted messages. Sand set breakpoints on the JavaScript encrypt and decrypt functions, recovered the encryption key, and built a utility to decode traffic. Messages had fields for type, data, user, and room. The room field read “admin.” By changing their join command from an empty room to “admin,” they connected to a live stream. They saw every victim typing name, address, and credit card data character by character. Victims who never clicked submit had already leaked everything.
Darcula and the Telegram Group
A debug message in the traffic contained the database name “Darcula.” Leiknes searched that word on Telegram. He found a user named Darcula who administered a group with nearly 500 members. Members bragged about their setup: Android phones with green tape over cameras, mobile modems, SIM card boxes, iPhones for iMessage, and racks of servers. They posted bank statements and videos of spending stolen money on first-class tickets, cars, and parties. Darcula remained quiet and only posted technical content, including installation instructions for the phishing kit.
Cracking the Licensing Server
The phishing platform, called Magikat, was written in Node.js and obfuscated with an open-source tool. Sand deobfuscated the code and found it contained licensing server logic. With a simple Nginx config, they tricked the software into thinking it was its own authorization server. This revealed a hidden menu to generate license keys. They created a key with a multi-year expiration. They then fingerprint-scanned the internet using Shodan and found the real licensing server hosted in Los Angeles. From it they extracted 5,000+ licenses issued in four months.
Identifying the Developer
Using access logs from the licensing server, Sand and Leiknes found the admin’s IP. That IP resolved to a VPN in Alibaba Cloud in Hong Kong. Passive DNS linked it to a domain, which linked to a GitHub account. The GitHub account had repositories deleted around the time Magikat launched. A URL shortener email sent to that account logged the same IP. Internet Archive saved a deleted tar file containing a Word document with Chinese author metadata. That name matched metadata in PDFs Darcula uploaded to Telegram. The developer was Yuang Chong.
Scale and Aftermath
The researchers provided a 24-page report to Norwegian police, Europol, and the FBI. They estimated over 200 impersonated brands, 5,000+ licenses, up to 600 active scammers, 13 million link clicks, and 900,000 stolen credit cards. Some victims lost $10,000. Norwegian state media worked with international outlets to travel to Thailand and confront the scammers. After being contacted for comment, Darcula deleted everything. No updates came after. Successor kits such as Magic Mouse appeared, with 1,300 servers in one month and an estimated 650,000 cards stolen per month.
Notable Quotes
“you should not click the link and you should delete the message” Erlend Leiknes · ▶ 2:01
“this is exactly what we saw when we joined the admin room it was a real time stream of everybody that was connected to that fishing site” Harrison Sand · ▶ 7:36
“they had issued over 5,000 licenses and we could see who had bought them and also where it was activated from” Harrison Sand · ▶ 18:53
“the link had been clicked on 13 million times” Harrison Sand · ▶ 29:15
“the mouse killed the cat” (Screenshot caption) · ▶ 35:06
Key Takeaways
- Phishing kits can include real-time admin panels that stream victim data as it is typed.
- Open-source obfuscation tools can be reversed, exposing licensing servers and developer identities.
- Law enforcement and media cooperation can disrupt infrastructure, but successor kits appear quickly.
About the Speaker(s)
Harrison Sand is a software and application security specialist with experience in embedded devices and IoT. He has worked in penetration testing, incident response, embedded security, and vulnerability management. His research has been featured in TechCrunch, PC Magazine, The Register, Ars Technica, Hackaday, Aftenposten, and NRK.
Erlend Leiknes is a security consultant and retired bus driver with a background in electrical engineering and a master’s degree in technical societal safety. He has spent over a decade at mnemonic performing penetration testing, red teaming, and security research. Several CVEs carry his name, and some are favored by APTs.