The Milk Dragon phishing kit, also referred to as NaiLong, has emerged as a sophisticated tool for online fraudsters, using advanced methods to bypass multi-factor authentication (MFA). This campaign, active since October 2025, entices online shoppers through enticing yet fraudulent deals.
Unlike traditional phishing strategies that rely on alarming emails, Milk Dragon places harmful links in marketplace ads and social media posts. When users click on these appealing discounts, they are redirected to fake retail sites demanding sensitive payment information.
Global Reach and Subscription Model
Researchers from Group-IB have identified Milk Dragon activities in 66 countries, uncovering 258 phishing pages since its inception. The operation includes templates mimicking 36 financial institutions for verification purposes.
The kit’s availability as a subscription service on Telegram significantly lowers the barriers for executing sophisticated fraud campaigns. Priced at 300 USDT per month, subscribers benefit from continuous updates and support for their phishing infrastructure.
Technical Mechanisms and Real-Time Threats
Milk Dragon’s tactics begin with advertisements offering unrealistically low prices on everyday items, hosted by accounts boosted with AI-generated content or artificial followers. Once engaged, victims are led to a WordPress site mimicking a legitimate retailer using WooCommerce for checkout.
A malicious plugin, BytePress, facilitates the scam by adding fake payment options and connecting to a backend controlled by the fraudsters. This setup enables real-time interaction through a Socket.IO WebSocket connection, allowing operators to manipulate the checkout process and intercept user inputs character by character.
Social Media and Phishing-as-a-Service
The phishing strategy capitalizes on casual social media browsing, presenting fraudulent offers that seem like genuine shopping deals without the urgency typical of phishing scams. This approach broadens the threat landscape by exploiting the growing trend of social commerce.
Milk Dragon’s flexible templates adapt to different regions and banks, reflecting a shift towards phishing-as-a-service models that facilitate real-time authentication bypass. This method is more advanced than traditional password collection techniques.
To protect themselves, consumers should scrutinize enticing offers and verify retailers independently before sharing payment details. Organizations need to monitor for suspicious domain names and deceptive checkout processes, taking proactive measures to dismantle fraud networks.
Ultimately, the Milk Dragon case highlights the need for improved digital vigilance and robust authentication practices to mitigate the risks posed by modern phishing schemes.
