The Darcula phishing framework continues to evolve, transitioning from early API-driven roots to a sophisticated “Phishing-as-a-Service” model using encrypted WebSockets and wrapper APIs. Our latest research uncovers the inner workings of Darcula, its expansion into fake e-commerce storefronts via the “NewBee” and “PandaShop” ecosystems, and its persistent targeting of government and financial institutions worldwide. Discover how this Chinese-backed operation maintains a global footprint through