Milk Dragon phishing kit steals card data keystroke by keystroke from fake discount shops
Group-IB says the Milk Dragon kit has produced 258 phishing pages hitting victims in 66 countries, using fake 3D Secure screens to capture one-time passcodes in real time.
At a glance
- Group-IB links 258 phishing pages to the kit, with victims in 66 countries and 21 impersonated consumer brands
- A custom WordPress plugin opens a WebSocket channel that relays what the victim types in the checkout form as they type it
- 36 bank-specific templates let the operator show a matching fake 3D Secure page and relay the one-time passcode to the real payment processor
- The kit is sold as a service on Telegram from 300 USDT per month, with Docker packaging that makes setup a single step
A phishing kit sold on Telegram is turning social media discount ads into real-time card theft, according to research published by Group-IB and reported on 5 October by Help Net Security. The kit, tracked as Milk Dragon and also known as NaiLong, has been active since October 2025; Group-IB says it has identified 258 phishing pages tied to the operation, with victims in 66 countries and 21 well-known consumer brands impersonated across cosmetics, fashion, food and beverage, home and baby products, and toys.
What makes the campaign notable is not the lure but the checkout. Group-IB describes an adversary-in-the-middle chain that keeps the victim inside a convincing purchase flow while the operator watches and intervenes live.
How the lure works
Rather than the usual fake fines or bank alerts, Milk Dragon leans on the fear of missing out. Group-IB reports that operators post native-looking social media listings and fake profiles advertising steep discounts on genuine brands, distributed through Facebook and TikTok marketplace advertisements. Named examples in the research include LEGO, Calvin Klein and Aeon Malaysia, alongside regional supermarket chains. Malaysia, Indonesia and Thailand are the most affected countries, though Group-IB notes the 66-nation footprint points to broad, largely indiscriminate targeting through social ad networks.
Technical details
The fraudulent stores are WordPress sites running WooCommerce. Group-IB found that a custom plugin called BytePress opens a WebSocket connection, built on socket.io, to the operator's command-and-control server. That channel gives the operator real-time keystroke capture and the ability to manipulate the form while the victim is still filling it in.
Once the card details are submitted, the victim is shown a fake 3D Secure verification page. Group-IB says the operator watches a "Live Session" log of the victim's activity and picks a matching page from 36 bank-specific templates, then relays the one-time passcode the victim enters back to the legitimate payment processor. A fake order confirmation page follows, which Group-IB says delays the moment the victim realises anything is wrong.
The operator panel supports role-based access for affiliates, centralised storage of harvested cards and device metadata, automatic card classification by BIN, and Telegram bot alerts for new submissions. Group-IB reports the kit is sold as a service from 300 USDT per month and ships in a containerised Docker deployment that makes command-and-control setup close to a single step for less skilled actors.
What to do
For shoppers, Group-IB and Help Net Security give the same advice: treat a steep, time-limited discount reached through a social media ad as a warning sign rather than an opportunity, and check the destination link with a service such as VirusTotal, urlscan.io or ScamAdviser before entering card details. Because this kit defeats one-time passcodes by relaying them, entering an SMS or app code on the attacker's page does not protect the transaction. Anyone who has submitted card details on a suspect site should contact their card issuer immediately rather than waiting for a charge to appear.
For brands and banks, Group-IB recommends monitoring lookalike domains and starting takedowns early, and watching for checkout pattern anomalies and suspicious card activity that fit this flow.
Sources
- Milk Dragon (NaiLong) phishing kit — Group-IB
- Fake brand discounts on social media prey on shoppers' fear of missing out — Help Net Security
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



