A new large-scale SMS phishing scheme, dubbed “Magic Mouse,” has emerged to replace the now-defunct “Magic Cat” scam, security researchers told TechCrunch. The operation is already stealing hundreds of thousands of credit card numbers each month, posing a growing threat to consumers worldwide.
Magic Cat — run by a 24-year-old Chinese national known as “Darcula” — was unmasked earlier this year by Oslo-based cybersecurity firm Mnemonic and Norwegian media, revealing the developer’s real identity as Yucheng C. His software enabled hundreds of scam operators to send fake delivery or government notices via text message, luring victims to phishing sites that harvested their payment card details. Over seven months in 2024, the scam netted at least 884,000 stolen cards before going dark.
In its wake, Mnemonic offensive security consultant Harrison Sand told TechCrunch that Magic Mouse has quickly outpaced its predecessor. The new operators have reportedly stolen phishing kits from Magic Cat, enabling them to replicate legitimate websites from major tech firms, consumer brands, and delivery companies to trick victims.
Investigators found Telegram posts showing racks of smartphones used to blast scam messages and mobile wallets loaded with stolen cards, ready for fraudulent purchases. Sand estimates the group is stealing about 650,000 cards each month, using payment terminals and digital wallets to launder funds into bank accounts.
Despite the massive scale of both operations, Sand noted that law enforcement response remains limited, with tech companies and financial institutions left to shoulder much of the responsibility for stopping such schemes.
For consumers, the advice remains simple: if you receive a suspicious or unexpected text message — especially one requesting payment — the safest move is to ignore it.

