threat_intelligence2679 wordsRead on Huntaegis

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Introduction Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message. But some lures are designed to find you where your guard is at its lowest: your social media feed. Picture this. You’re doomscrolling late at night when an advertisement catches your eye. A brand you know and trust, selling products you actually want, at a discount that seems too good to pass up. No urgent warnings, no “act now or else,” no red flags screaming for attention. Just a deal that seems to pop up organically. That’s exactly what makes it dangerous: these attacks strike when your brain is on autopilot. In this blog, we dissect Milk Dragon (also known as NaiLong), a phishing kit behind campaigns promoting fake discounts to steal credit card information. We’ll break down how it spreads, walk through the full attack flow, and show something rarely seen from the outside: the affiliate panel where operators watch your stolen data roll in and the Telegram community where affiliates congregate. Key Discoveries - Victims spanning 66 countries, with 258 phishing pages identified since October 2025. - Phishing pages impersonate brands across multiple industries, including Retail & Supermarket chains. Well-known brand names such as LEGO, Calvin Klein, Aeon Malaysia, and many others are exploited and used as lures. - 36 distinct banking templates were used to conduct Adversary-in-the-Middle (AiTM) phishing attacks designed to bypass multi-factor authentication (MFA) protections. - Threat actors leveraged native social media posts promoting heavily discounted products as phishing lures to entice victims and drive traffic to fraudulent websites. - The Milk Dragon Phishing Kit was found to be actively sold on Telegram, with developers providing ongoing support and updates to affiliates and operators. - Identified and analyzed the phishing kit’s operator panel and custom plugins, revealing how threat actors manage campaigns and streamline large-scale phishing operations. Who may find this blog interesting: - Cybersecurity analysts and corporate security teams - Malware analysts - Threat intelligence specialists - Cyber investigators - Computer Emergency Response Teams (CERT) - Law enforcement investigators - Cyber police forces - Advertisement services - Online shoppers Group-IB Threat Intelligence Portal Group-IB customers can access our Threat Intelligence portal for more information about this threat actor / malware: Victimology Group-IB Threat Intelligence team has identified Milk Dragon targets spanning 66 countries globally. The countries with the top victim counts are shown below: During ongoing monitoring, Group-IB Threat Intelligence have observed a total of 21 popular brands across the cosmetics & fashion, food & beverage products, home & baby products, and toy industries, including regional supermarkets as targets of impersonation. Milk Dragon was also observed impersonating 36 financial institutions through MFA phishing templates designed to capture MFA credentials. Group-IB customers can view the full list of impersonated brands on our Threat Intelligence portal. Telegram Distribution The Milk Dragon Phishing kit has been sold as a Phishing-as-a-Service (Phaas) in Telegram communities since at least October 2025. The distribution model requires buyers to pay a monthly or yearly subscription fee to maintain access to the phishing panels. The tool is being sold from 300 USDT per month with various subscription plans and add-ons. Phishing Workflow Milk Dragon differentiates itself from the conventional phishing playbook in a notable way. Instead of inducing fear and urgency in victims through impersonation of fines, parcel delivery issues, or banking alerts, the kit’s operators distribute malicious links through legitimate marketplaces such as Facebook and TikTok e-commerce listings, luring victims with huge exclusive discounts on popular brands and consumer goods. It hooks victims with a different kind of fear, the fear of missing out (FOMO). This distribution model embeds malicious links natively within these social media marketplaces, allowing threat actors to abuse the trust associated with these platforms. The organic nature of this model means that users don’t feel targeted, reducing suspicion that these malvertisements are anything other than a normal ad on these platforms. Attractive discounts on well-known brands and common everyday goods further reduce users’ suspicion, increasing the probability that victims will proceed with the phishing workflow with minimal hesitation. Phishing page showcase In this section, we examine some of the fake Facebook listings and phishing pages run by Milk Dragon operators observed by Group-IB analysts in this research. While we have not observed any indication that Milk Dragon offers distribution services for these malicious links, the seller recommends this tactic to prospective buyers. To further increase the effectiveness of the masquerade, such malvertisements have been posted using potentially fake profiles, often containing the same lures. Some of these profiles have been found to contain AI generated content, and may have possibly purchased followers to appear legitimate. Whether these accounts are managed by the operators themselves or by an underground distribution service is unclear at this moment. Once victims engage with the malicious advertisement on social media, they are redirected to a WordPress site disguised as a legitimate online retailer offering heavily discounted products. Rather than build a payment system from scratch, the phishing page is hosted on a WordPress site that uses WooCommerce, a legitimate e-commerce plugin, to generate payment/checkout pages where a victim inputs sensitive financial information. A second, custom plugin (called BytePress) is installed alongside WooCommerce, facilitating command-and-control (C2) communication and allows an operator to direct the victim through a sequence of checkout steps, pages, and notifications, in real time. After submission of payment details, the victim will encounter a fake turnstile loading page for the operator to redirect the user to complete the specific multi-factor authentication (MFA) issued by a legitimate 3DS site. After the operators successfully steal the MFA and payment details, victims are redirected to a fake confirmation page to carry on the deception. This continues to trick victims into thinking that nothing is amiss and that they have completed a legitimate e-commerce process, decreasing the odds of suspicions and preventing immediate anti-fraud remediation actions such as card cancellations. BytePress Plugin Phishing pages associated with the Milk Dragon phishing kit makes use of a custom plugin to communicate with the phishing C2 panel, allowing the operator to manage the malicious payment pages displayed, as well as to steal sensitive information in real time. On installation and activation, the BytePress plugin adds fraudulent payment options to the WooCommerce checkout, a fake credit-card method and a fake PayPal method. BytePress also has its own settings page accessible via WordPress admin, where the operator enters the address of their C2 panel in a field labelled “API Base URL”. This field links the fraudulent checkout to the operator’s backend. Once configured, the BytePress plugin establishes a communication channel between the checkout page running in the victim’s browser and the operator’s C2 server via a persistent WebSocket (socket.io) connection. This channel lets the operator control the victim’s experience in real time; directing them to additional pages, accepting, rejecting, or blocking submitted payment information, and displaying custom notifications, while simultaneously exfiltrating the stolen data. Using this WebSocket connection, the victim’s inputs on the payment page are streamed to the panel character by character, without requiring the victim to trigger a form submission. As part of continued development support, operators will also be notified of updates made to the Milk Dragon plugin via the phishing panel where they would also be able to download the latest version and push to their own-managed phishing pages. Phishing Panel The Milk Dragon Phishing kit enables operators to manage and coordinate multiple phishing campaigns at scale through a custom Milk Dragon phishing panel. The panel provides the following features: - Multi-account management – multiple accounts with specific roles can be created for affiliates to grant access to subordinate operators as well as to manage permissions for specific functions. - Real-time phishing management – Phishing panel is connected directly to live phishing pages, where an operator can change the phishing page that is being displayed to the victim, directing them to input different information to be stolen. - Automated notifications – Operators are notified of new victim activity or input submission via an in-browser notification. Telegram notifications can be configured as well via Telegram bots. - Configurable card BIN identification – Panel can be configured to automatically tag each credit card according to type and issuing bank according to BIN numbers. - Centralized storage – All information are stored on the panel, from domain visits to conversion rates, visitor details and credit card information are all stored on the panel for operators to view. After purchasing the phishing kit, the buyer will be directed to the Milk Dragon Installation page (shown above) where affiliates are able to install and update their phishing panels. On this installation page, affiliates would provide the IP/domain, SSH port, as well as SSH credentials, which will be used to automatically deploy a containerised instance of the phishing panel via a Docker Image. Necessary resources such as SQL database, API services etc. will also be set up automatically. This installation/setup can potentially be done via a single click, allowing affiliates to setup a phishing C2 panel as long as they have the infrastructure available. The dashboard gives operators centralized visibility into the performance of all phishing sites tied to the panel. For each site, it shows key metrics including visitor counts, total orders submitted and completed payments, allowing operators to gauge the effectiveness of individual campaigns at a glance. The panel is built to support large scale operations, as the architecture allows a single panel to manage a many-to-one relationship with multiple phishing pages simultaneously. The panel retains a centralized record of all harvested data, including payment card details, personal information, device/equipment meta data, and fraudulent order details, accessible to affiliates for future reference. This creates a reusable victim profile, enabling affiliates to re-target individuals who have previously fallen for the scheme. The screenshot above demonstrates the Milk Dragon plugin’s keylogging capability, which streams victim input from the phishing page to the operators in real time. The panel provides a user interface that allows operators to monitor victim activity in real time, displayed under the “Live Session” section on the right side of the figure above. On the left, the panel presents all relevant information the victim has entered or selected, giving operators a consolidated view of the captured data alongside the live session feed. The console reveals the adversary-in-the-middle (AiTM) capability that lets the operator manipulate the victim’s session in real time. Once a victim submits their payment details, the operator selects the corresponding verification method within the panel that mirrors the specific 2FA challenge issued by the legitimate 3DS payment site. Once the victim enters the one-time password (OTP) in the spoofed verification page, the operator can relay it to authorize a fraudulent transaction or take over the account. The panel provides a custom build page that allows affiliates to create verification templates to match the campaign’s geolocation. Affiliates can build the page element by element or select a given template to edit. Across all panels investigated, Group-IB analysts identified 36 different financial institution impersonation templates. The kit’s role-based access provides scam syndicates with an easily managed phishing framework without the need to purchase multiple subscriptions. This leads to a lower barrier of entry for less skilled malefactors and increases the volume of victims a single deployment can process, as multiple victims are funneled into a single C2 server. Conclusion Phishing has outgrown the email inbox and people have begun to be suspicious of unsolicited texts. The Milk Dragon phishing kit shows how threat actors are pivoting to exploit virtually every digital touchpoint turning trusted spaces into attack vectors. The evolution doesn’t stop at distribution channels. Actors continuously refine their trade craft, utilizing new hooks such as fake discounts, pairing them with real-time, operator-driven OTP relays to defeat 3D Secure (3DS) and other MFA checks, and backing it with proper C2 infrastructure rather than a static drop server. Such kits are becoming more accessible and lowers the bar for less-skilled actors to run operations that once required custom development. Milk Dragon’s sophistication is not an anomaly. It is the new standard. As defenses improve, attackers adapt: they abandon crude fear-based lures for organic, frictionless, and intent-aligned attacks where victims engage willingly. They automate at scale, professionalize operations, and build sustainable criminal operations. The takeaway is clear: email-centric security awareness and multi-factor authentication are no longer sufficient on their own. Threats now arrive through social commerce, advertisements, and messaging platforms. Vigilance must extend across every digital channel, and verification must become a reflexive habit, especially when a deal seems too good to pass up. Recommendations For Enterprises: - Monitor for lookalike domains, and initiate takedown action before campaigns scale. - Monitor for suspicious card activity and unusual checkout patterns to catch compromised cards before they’re monetized. - Integrate an advanced Threat Intelligence solution to identify emerging phishing kits early. For Individuals: - Stay skeptical while scrolling, advertisements and third party links on social media are now a potential phishing vectors. - Treat steep discounts as a red flag, especially for limited-time offers designed to rush your decision - If you fall prey to such scams, immediately notify your bank or credit card company. - Verify links from advertisements and unfamiliar shops before entering card details using free reputation tools such as urlscan.io, VirusTotal, or ScamAdviser. Frequently Asked Questions (FAQ) How is Milk Dragon different from other phishing kits? While Milk Dragon’s technical capabilities (AiTM, real-time credential capture) are not unique, its distribution model is. Instead of relying on emails or SMS, Milk Dragon spreads through social media advertisements and native posts on platforms like Facebook and TikTok. This allows it to reach victims in trusted spaces where their guard is naturally lower, significantly reducing friction compared to traditional email-based phishing or SMS phishing (Smishing). What is a 3D Secure payment site 3D Secure payment sites are known as 3DS sites where there is an enhanced protocol for online credit and debit card transactions. It requires a two-factor authentication (2FA) for the transaction to be completed. What is Phishing-as-a-Service (PhaaS)? Phishing-as-a-Service (PhaaS) is a scalable, subscription-based cybercrime model that lowers the technical barrier to entry for threat actors. By using a PhaaS, cybercriminals can rapidly deploy fraudulent campaigns and replicate proven attack workflows with minimal technical overhead. It is a similar operating model to Ransomware-as-a-Service (RaaS), which you can read more about on the Group-IB Knowledge Hub. What qualifies as an Adversary-in-The-Middle kit An AiTM phishing kit goes beyond traditional phishing by acting as a real-time proxy between the victim and the legitimate website. Rather than simply harvesting credentials from a static fake page, an AiTM kit forwards the victim’s input to the real site and relays the response back, creating a live session that allows the attacker to intercept authentication tokens and session cookies in addition to usernames and passwords. Indicators of Compromise (IOCs) This data is deemed sensitive and cannot be published publicly, but Group-IB customers can access the full list of IOCs on our Threat Intelligence portal. DISCLAIMER: All technical information, including malware analysis, indicators of compromise and infrastructure details provided in this publication, is shared solely for defensive cybersecurity and research purposes. Group-IB does not endorse or permit any unauthorized or offensive use of the information contained herein. The data and conclusions represent Group-IB’s analytical assessment based on available evidence and are intended to help organizations detect, prevent, and respond to cyber threats. Group-IB expressly disclaims liability for any misuse of the information provided. Organizations and readers are encouraged to apply this intelligence responsibly and in compliance with all applicable laws and regulations. This blog may reference legitimate third-party services such as Telegram and others, solely to illustrate cases where threat actors have abused or misused these platforms. This material is provided for informational purposes, prepared by Group-IB as part of its own analytical investigation, and reflects recently identified threat activity. All trademarks referenced herein are the property of their respective owners and are used solely for informational purposes, without any implication of affiliation or sponsorship.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.