# Milk Dragon

> As of 2026-10-04, Milk Dragon is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. ATT&CK coverage spans 14 techniques across 8 tactics in 2 of 2 tracked threats. Most-observed techniques: T1056.001 (Keylogging), T1056.003 (Web Portal Capture), T1071.001 (Web Protocols).

- **Tracked threats:** 2
- **Categories:** PHISHING
- **As of:** 2026-10-04

## ATT&CK techniques observed

14 techniques observed across 2 of 2 tracked threats. Tactics: Credential Access (4), Resource Development (3), Command and Control (2), Stealth (formerly Defense Evasion) (2), Collection (1), Execution (1).

- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Collection — observed in 2 of 2 tracked threats
- [T1056.003](https://intel.threadlinqs.com/technique/T1056.003) Web Portal Capture — Credential Access — observed in 2 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 2 tracked threats
- [T1111](https://intel.threadlinqs.com/technique/T1111) Multi-Factor Authentication Interception — Credential Access — observed in 2 of 2 tracked threats
- [T1204.001](https://intel.threadlinqs.com/technique/T1204.001) Malicious Link — Execution — observed in 2 of 2 tracked threats
- [T1566.003](https://intel.threadlinqs.com/technique/T1566.003) Phishing — Initial Access — observed in 2 of 2 tracked threats
- [T1583.001](https://intel.threadlinqs.com/technique/T1583.001) Domains — Resource Development — observed in 2 of 2 tracked threats
- [T1585.001](https://intel.threadlinqs.com/technique/T1585.001) Establish Accounts — Resource Development — observed in 2 of 2 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 2 tracked threats
- [T1684.001](https://intel.threadlinqs.com/technique/T1684.001) Impersonation — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1090.002](https://intel.threadlinqs.com/technique/T1090.002) External Proxy — Command and Control — observed in 1 of 2 tracked threats
- [T1480](https://intel.threadlinqs.com/technique/T1480) Execution Guardrails — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1557](https://intel.threadlinqs.com/technique/T1557) Adversary-in-the-Middle — Credential Access — observed in 1 of 2 tracked threats
- [T1583.008](https://intel.threadlinqs.com/technique/T1583.008) Acquire Infrastructure: Malvertising — Resource Development — observed in 1 of 2 tracked threats

## Tracked threats

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA](https://intel.threadlinqs.com/threat/TL-2026-2919) — HIGH
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA](https://intel.threadlinqs.com/threat/TL-2026-2901) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Milk%20Dragon
