Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
Milk Dragon uses fake social-media discounts to steal cards and intercept 3-D Secure codes.
Group-IB reported that the Milk Dragon phishing-as-a-service kit, also called NaiLong, uses discounted Facebook and TikTok posts to send victims to fraudulent stores. Since October 2025 it has linked 258 pages to victims in 66 countries, with 36 banking templates and impersonation of 21 brands, including LEGO, Calvin Klein, and Aeon Malaysia. A malicious WordPress plugin, BytePress, inserts fake card and PayPal checkout options and streams entered data to operators, who proxy legitimate 3-D Secure challenges to capture codes. The kit has been sold on Telegram from 300 USDT per month with an operator panel and live session monitoring.
- Group-IB linked 258 pages since October 2025 to victims in 66 countries.
- Discount posts on Facebook and TikTok lead to fake WooCommerce stores.
- The BytePress plugin streams checkout input over Socket.IO WebSockets.
- Operators relay real 3-D Secure prompts and capture one-time codes.
- Subscriptions have been sold on Telegram from 300 USDT per month.
Full article768 words · extracted from gbhackers.com · click to collapse
A phishing-as-a-service operation dubbed Milk Dragon, also known as NaiLong, is abusing discount-themed Facebook and TikTok posts to steal payment-card data and intercept multi-factor authentication (MFA) challenges.
Group-IB identified 258 phishing pages linked to the kit since October 2025, with victims across 66 countries.
Rather than relying on classic delivery-failure notices, bank alerts, or account-lockout messages, Milk Dragon operators exploit social-commerce behavior.
Victims encounter posts advertising heavily discounted consumer goods from recognizable brands, then are redirected to fraudulent storefronts that imitate legitimate e-commerce sites.
The approach weaponizes fear of missing out: a seemingly organic offer in a trusted social-media feed can appear far less suspicious than an unsolicited email or SMS.
Examples cited in the research include LEGO, Calvin Klein, and Aeon Malaysia.
The campaigns do not merely target card details; they also use 36 banking templates designed to capture authentication data and enable adversary-in-the-middle, or AiTM, fraud.
The infection chain begins with Facebook or TikTok marketplace-style advertisements and native-looking posts promising exceptional discounts.
Threat actors may use fake profiles populated with AI-generated content and artificially inflated follower counts to strengthen the illusion of legitimacy.
After clicking the lure, the target arrives at a WordPress-based phishing site styled as an online retailer.
The malicious storefront uses WooCommerce, the legitimate WordPress e-commerce plugin, to create convincing product, cart, and checkout workflows.
This use of familiar software reduces the effort needed to build a believable shopping experience and helps operators rapidly deploy new brand-impersonation pages.
Milk Dragon then adds a custom malicious WordPress plugin called BytePress.

The plugin inserts fraudulent credit-card and PayPal payment methods into the WooCommerce checkout and connects the site to the operator’s command-and-control infrastructure.
Group-IB observed the phishing kit, impersonating 21 brands across sectors including cosmetics, fashion, food and beverages, home and baby products, toys, and regional supermarket chains.
According to Group-IB, the connection uses persistent Socket.IO WebSocket communications, allowing data entered by victims to be streamed to attackers character by character rather than only after a form submission.
Milk Dragon Phishing Kit
Once a victim enters card details, the page can display a fake loading or “turnstile” screen while the operator chooses a verification page corresponding to the legitimate 3-D Secure authentication challenge.
The victim is then presented with a spoofed one-time-password or app-verification prompt.

By collecting and relaying the code in real time, operators can attempt to authorize fraudulent transactions before the code expires.
This illustrates a key limitation of OTP-based MFA: it helps protect a transaction only when users can reliably distinguish the authentic bank or payment-authentication flow from an attacker-controlled proxy.
The victim will encounter a fake turnstile loading page for the operator to redirect the user to complete the specific multi-factor authentication (MFA) issued by a legitimate 3DS site.
After harvesting the card details and verification code, Milk Dragon redirects targets to a counterfeit order-confirmation page.

This final step is operationally important because it delays suspicion, potentially buying fraudsters time before a victim contacts their bank or freezes the card.
Milk Dragon has reportedly been sold through Telegram communities since at least October 2025, with subscriptions starting at 300 USDT per month.
Buyers receive access to a centralized operator panel, ongoing updates, and support services.
The panel supports role-based accounts, multiple concurrent phishing sites, visitor and conversion tracking, card BIN tagging, live victim-session monitoring, Telegram alerts, and centralized storage of harvested personal and payment information.
Affiliates can reportedly deploy containerized panel instances through a streamlined setup workflow, reducing the technical skills required to run scalable payment-phishing operations.
Milk Dragon demonstrates that phishing has moved well beyond inboxes and text messages.
Users should treat extreme social-media discounts as a verification event: navigate to a retailer through its official app or manually entered website address, rather than following an ad’s embedded link.
Organizations should monitor for brand-abusing domains, social-media impersonation, lookalike checkout pages, and WebSocket-enabled data-exfiltration patterns associated with fraudulent payment flows.
For consumers who may have entered card data or a 3-D Secure code on a suspicious site, the immediate priority is to contact the card issuer, block or replace the card, review transactions, and avoid reusing any credentials submitted during the checkout process.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.