Security2 publishers2 min readPublished
Milk Dragon phishing kit relays shoppers' 3D Secure codes from fake brand discount shops
Group-IB tied the Milk Dragon phishing kit to 258 phishing pages and victims in 66 countries, baited with fake discounts posted on Facebook and TikTok. An operator then relays the victim's own 3D Secure code to approve the fraudulent charge.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The fake shops impersonate 21 brands across cosmetics, fashion, food, home and baby goods, toys and regional supermarkets, among them LEGO, Calvin Klein and Aeon Malaysia.
- Group-IB says the kit, also known as NaiLong, has been in use since October 2025.
- Operators get a browser or Telegram bot alert the moment a victim types data, and each stolen card is tagged by type and issuing bank from its BIN.
- The operator panels Group-IB examined held verification-page templates impersonating 36 financial institutions, and affiliates can build pages to match each target country.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Awareness training keyed to fear lures such as fines and delivery alerts gives shoppers little to recognise in a discount listing they scrolled into and did not feel targeted by.
- exposure The 3D Secure code protects nobody here: the cardholder types the real code into the spoofed page, and the operator uses it in the same session to approve the charge.
- exposure A victim who paid once stays in the panel as a profile with card, device and personal data, available to any affiliate for a second, better-informed approach.
Milk Dragon's operators drop the fake fines, parcel delivery problems and bank alerts built to cause fear and urgency. They post links in ordinary Facebook and TikTok marketplace listings offering large exclusive discounts on popular brands [3][4]. "It hooks victims with a different kind of fear, the fear of missing out (FOMO)," Group-IB's researchers wrote [5]. According to Group-IB, shoppers who find the links in a listing do not feel targeted and have fewer reasons to be suspicious, and the lures are designed to reach people scrolling on autopilot [7]. The research as reported does not test whether awareness training or brand-protection services catch these shops, and it does not put a figure on victims or losses [2][7].
Nobody knows yet who runs distribution. Some posts come from what look like fake profiles running AI-generated content, possibly with bought followers [8]. "Whether these accounts are managed by the operators themselves or by an underground distribution service is unclear at this moment," Group-IB wrote [9].
The theft happens live. A click lands the victim on a WordPress shop running WooCommerce, where a custom plugin called BytePress adds fake credit card and PayPal options to the checkout [10]. BytePress keeps a WebSocket open to the operator's command-and-control server. Every character typed into the payment form reaches the operator before the form is submitted [11]. Over that same connection the operator can accept, reject or block the card, send the shopper to other pages and push custom notifications [12].
Once the card is in, the victim sees a fake Turnstile loading page while the operator picks a spoofed page that mirrors the bank's 3D Secure challenge [13]. The victim types the genuine code from their bank into it. The operator passes that code straight on to push through a fraudulent payment or hijack the account [13]. A fake order confirmation closes the session and delays the victim cancelling the card [14].
The data does not leave the panel after the first theft. It keeps card details, personal information, device metadata and order details for every victim, and affiliates can go back to those records to target people who have already fallen for the scam once [17]. A dashboard tracks visitor counts, submitted orders and completed payments for each site tied to the panel [19].
Milk Dragon is built for affiliates. "The kit's role-based access provides scam syndicates with an easily managed phishing framework without the need to purchase multiple subscriptions," Group-IB's researchers wrote. They added that this lowers the barrier for less skilled criminals and lets one deployment process more victims through a single C2 server [16].
What to watch
- Whether Group-IB or the platforms establish who runs the fake Facebook and TikTok profiles: the Milk Dragon operators themselves or an underground distribution service.
- Any victim count or loss figure from Group-IB, card issuers or the impersonated brands; so far the campaign is sized only in phishing pages and countries.
- Panels carrying templates beyond the 36 financial institutions seen so far would show affiliates moving into new markets.