Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA
Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit (TL-2026-2834), also tracked as Milk Dragon, is a high-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects LEGO Consumer brand impersonated by fake storefronts (no, maps to 11 MITRE ATT&CK techniques (T1056.001, T1071.001, T1111), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-2834
- Threat ID
- TL-2026-2834
- Also known as
- Milk Dragon, NaiLong
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, ecommerce, finance, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit
Malware and tooling: Milk Dragon, NaiLong, telegram, Docker, Milk Dragon operator panel, WooCommerce, WordPress, socket.io
Group-IB details Milk Dragon (NaiLong), an Adversary-in-the-Middle phishing kit sold as PhaaS on Telegram from 300 USDT per month. It spreads through Facebook and TikTok marketplace ads and posts offering heavily discounted goods, using fake WordPress/WooCommerce storefronts and a custom 'BytePress' plugin for C2, real-time keystroke capture, and 3D Secure MFA interception and relay.
How Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit works
Milk Dragon (also tracked as NaiLong) is an Adversary-in-the-Middle (AiTM) phishing kit distributed as Phishing-as-a-Service (PhaaS) through Telegram communities, priced from 300 USDT per month with various subscription plans and add-ons. Group-IB reports it has been active since October 2025 and identified 258 phishing pages with victims across 66 countries. Unlike fear-based phishing, the lure is commerce: heavily discounted consumer goods advertised through Facebook and TikTok marketplace ads and organic posts, in some cases from potentially AI-generated profiles with purchased followers to appear legitimate. Impersonated storefronts span 21 consumer brands (cosmetics, fashion, food and beverage, home/baby products, toys; e.g. LEGO, Calvin Klein, Aeon Malaysia) plus regional supermarkets.
The phishing sites are fake WordPress/WooCommerce storefronts. A second, custom plugin called BytePress is installed alongside WooCommerce and provides the command-and-control link: it adds fake credit card and PayPal payment methods and exposes an 'API Base URL' configuration field that ties the fraudulent checkout to the operator's C2 panel. BytePress keeps a persistent socket.io WebSocket connection to the panel, streaming the victim's input character by character without a form submission, so card data is captured in real time even if the checkout is abandoned.
The operator panel is connected directly to live phishing pages. It supports multiple accounts with role-based access control, Telegram bot notifications on victim activity, BIN-based card identification with automatic bank tagging, live session monitoring with keystroke capture, and centralized storage of domain visits, conversion rates, visitor details and card data. The panel is deployed in Docker through an automated installer that uses SSH credentials and auto-provisions the SQL database and API services; hosting is supplied by affiliates.
After card capture, the operator steers the victim to a matching 3D Secure/OTP page. The kit has 36 financial-institution impersonation templates for 2FA/3DS pages, customizable by geolocation. The victim enters the one-time code on the spoofed page and the operator relays it to the legitimate 3DS site to authorize a fraudulent transaction or take over the account. A fake turnstile loading page serves as a distraction during the relay, and the victim is then shown a fake confirmation page. Collected data is retained in the panel for re-targeting.
Group-IB states that full IOCs are restricted to its customers (Threat Intelligence portal), and the report names no individual actors, domains, IPs or hosting providers. No CVEs are involved; the kit abuses legitimate software (WordPress, WooCommerce, socket.io, Docker) and legitimate platforms (Facebook, TikTok, Telegram). Attribution is therefore unknown. The IOC set below is limited to publicly stated artifacts (tooling, platforms, behaviors, impersonated brands).
MITRE ATT&CK techniques used in TL-2026-2834
Collection
Command and Control
Credential Access
T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle
Execution
Initial Access
T1566.003 Spearphishing via Service
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1587.001 Malware
Impact
Defense Evasion
Affected products and versions in Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit
- LEGO — Consumer brand impersonated by fake storefronts (no vulnerability)
- Calvin Klein — Consumer brand impersonated by fake storefronts (no vulnerability)
- Aeon Malaysia — Retailer impersonated by fake storefronts (no vulnerability)
- Various financial institutions (36 templates) — 3D Secure / OTP pages spoofed for MFA relay (no vulnerability)
Remediation for Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit
Immediate actions
- Monitor for lookalike domains impersonating your brand and initiate takedown before campaigns scale
- Monitor for unusual checkout patterns on e-commerce properties
- If a card was entered on a suspect shop, immediately notify the bank or card issuer
Workarounds
- Verify suspicious shop links with UrlScan.io, VirusTotal or ScamAdviser before purchase
- Treat any OTP/3DS prompt that appears outside the bank's own app or flow as suspicious
Longer-term hardening
- Integrate threat intelligence on PhaaS kits and impersonated-brand storefronts into brand-protection workflows
- Educate customers that steep, limited-time discounts on social media are a red flag
Timeline of Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit
- Kit offered as PhaaS in Telegram communities from 300 USDT per month with subscription plans and add-ons (start of sales not dated precisely; observed from October 2025 activity window)
- Earliest of the 258 phishing pages Group-IB identified since October 2025 (month precision)
- Milk Dragon (NaiLong) PhaaS kit becomes active (Group-IB: 'since October 2025'; exact day not stated, month precision)
- Group-IB states full IOC list is available only to customers via its Threat Intelligence portal; no domains, IPs or hosting providers published
- Group-IB publishes 'Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy'
- As of Group-IB's report, 258 phishing pages, victims in 66 countries, 21 impersonated consumer brands and 36 financial-institution MFA templates
Sources cited for Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit
- Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy
- Group-IB: Phishing kits (background)
- Group-IB: Telegram bots and Google Forms used to automate phishing (background on Telegram exfiltration)
- MITRE ATT&CK T1557 Adversary-in-the-Middle
- MITRE ATT&CK T1111 Multi-Factor Authentication Interception
- MITRE ATT&CK T1566.003 Phishing: Spearphishing via Service
- MITRE ATT&CK T1656 Impersonation
More in phishing
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
Detection coverage for TL-2026-2834
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2834 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.