Milk Dragon phishing kit lures shoppers with fake discounts

Milk Dragon phishing kit lures shoppers with fake discounts

A phishing kit called Milk Dragon is luring online shoppers with fake brand discounts on Facebook and TikTok, then stealing their payment card details and one-time passwords, according to Group-IB.

The kit, also known as NaiLong, has been active since October 2025. Researchers linked it to 258 phishing pages and to victims in 66 countries.

FOMO instead of fear

Most phishing campaigns try to scare people into acting quickly. Common lures include fake fines, parcel delivery problems or alerts from a bank. Milk Dragon's operators take a different route. They place malicious links in social media marketplace listings and offer large, exclusive discounts on popular brands and consumer goods.

"Milk Dragon differentiates itself from the conventional phishing playbook in a notable way," Group-IB noted. "It hooks victims with a different kind of fear, the fear of missing out (FOMO)," the researchers wrote.

The fake shops impersonate 21 brands across cosmetics and fashion, food and beverage, home and baby products, and toys. Regional supermarkets are also on the list. LEGO, Calvin Klein and Aeon Malaysia are among the names used as bait.

Group-IB said the placement matters. The links sit in ordinary marketplace listings, so users don't feel singled out and have fewer reasons to be suspicious. The lures are built to catch people while they scroll without paying much attention.

Some posts come from what look like fake profiles that carry AI-generated content and may have bought followers. "Whether these accounts are managed by the operators themselves or by an underground distribution service is unclear at this moment," the researchers said.

A checkout page that streams every keystroke

A victim who clicks on the ad or post lands on a WordPress site dressed up as an online retailer with discounted products. The store runs on WooCommerce, a legitimate e-commerce plugin. A custom plugin called BytePress adds a fake credit card option and a fake PayPal option to the checkout.

BytePress also keeps a persistent WebSocket connection open between the checkout page and the operator's command-and-control (C2) server. Anything the victim types into the payment form reaches the operator character by character, before the form is even submitted. The same channel lets the operator send the shopper to other pages, accept, reject or block the card, and show custom notifications.

Once the card details are sent, the victim sees a fake Turnstile loading page. While it is displayed, the operator picks a spoofed verification page that copies the two-factor challenge from the legitimate 3D Secure (3DS) payment service, the extra check many card issuers use to confirm online purchases. When the victim types in the one-time password, the operator relays it to approve a fraudulent transaction or to take over the account.

The last step is a fake order confirmation. This keeps victims from growing suspicious and delays actions such as cancelling the card.

Victims turned into reusable profiles

Group-IB examined the kit's operator panel and custom plugins, which show how the criminals run and scale their campaigns.

"The dashboard gives operators centralized visibility into the performance of all phishing sites tied to the panel. For each site, it shows key metrics including visitor counts, total orders submitted and completed payments, allowing operators to gauge the effectiveness of individual campaigns at a glance," the researchers explained.

For every victim, the panel stores payment card details, personal information, device metadata and order details. Affiliates can come back to these records later. Each victim becomes a reusable profile, and people who were tricked once can be targeted again.

Operators receive an alert in the browser or through a Telegram bot whenever a victim enters data. Each stolen card is tagged by type and issuing bank based on its BIN, the first digits of the card number. A live session view shows what the victim is doing alongside the data they have entered.

Affiliates can also create fake verification pages matching the country a campaign targets. The panels Group-IB examined held templates impersonating 36 financial institutions.

"The kit's role-based access provides scam syndicates with an easily managed phishing framework without the need to purchase multiple subscriptions. This leads to a lower barrier of entry for less skilled malefactors and increases the volume of victims a single deployment can process, as multiple victims are funneled into a single C2 server," the researchers added.

Group-IB advises users to be careful with ads and third-party links on social media, and to treat steep or time-limited discounts as a red flag. Anyone who has entered card details on such a site should contact their bank or card issuer immediately. Companies should look out for lookalike domains, request takedowns early, and monitor for suspicious card activity and unusual checkout patterns.

Our Take

Milk Dragon shows that phishing does not need to frighten people to work. A bargain can be just as effective, especially when it shows up in a feed people already trust. Social platforms keep turning into delivery channels for fraud, whether through hijacked brand accounts, such as the recent case where Microsoft's X account was used to push a crypto token, or through the kind of social engineering scams now reaching bank customers in many countries.

The real-time relay of one-time passwords is the more worrying detail. It suggests that 3DS checks on their own do not stop a live operator from getting the code a victim types in. The panel's affiliate model also points to phishing sold as a managed service, with less skilled criminals able to join in.

It is worth watching whether platforms remove these marketplace listings faster, and whether Group-IB or others can establish who runs the fake profiles.