Threat reportPhishingTL-2026-2901
Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA
Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses (TL-2026-2901), also tracked as NaiLong phishing kit, is a high-severity phishing campaign, first published 2026-10-04. It is attributed to Milk Dragon with low confidence, affects Online shoppers / card holders Payment cards protected by 3D Secure, maps to 13 MITRE ATT&CK techniques (T1056.001, T1056.003, T1071.001), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK
- Actors
- 1Milk Dragon
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-2901
- Threat ID
- TL-2026-2901
- Also known as
- NaiLong phishing kit, BytePress phishing kit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Milk Dragon
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, finance, ecommerce, consumer
- Target regions
- Southeast Asia, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses
Malware and tooling: Milk Dragon, NaiLong, telegram, Socket.IO
How Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses works
Milk Dragon (aka NaiLong) is a subscription phishing-as-a-service kit, active since October 2025, that runs card-fraud storefronts on WordPress/WooCommerce and relays 3D Secure OTPs to operators in real time. Group-IB identified 258 phishing pages across 66 countries, 36 financial-institution OTP templates and 21 impersonated brands.
Group-IB (published 2026-10-01) describes Milk Dragon, also tracked as NaiLong, a Telegram-sold phishing-as-a-service (PhaaS) kit that has been active since at least October 2025. Victims are lured by Facebook and TikTok marketplace listings and ads, posted from AI-generated profiles with purchased follower bases, offering steep discounts on well-known brands (examples named: LEGO, Calvin Klein, Aeon Malaysia; 21 brands in total across cosmetics, fashion, food and beverage, home and baby products, toys and regional supermarket chains). The lure leans on fear of missing out on a bargain rather than the fear or urgency used by classic phishing, and the traffic arrives from ordinary-looking social ads, which lowers suspicion.
The landing sites are WordPress stores running WooCommerce. A custom malicious plugin, BytePress (also referred to as the 'SP plugin'), adds fraudulent card and PayPal payment options to the WooCommerce checkout and acts as the C2 and operator-control component. The operator enters the address of their C2 panel in a plugin settings field labelled 'API Base URL'. BytePress then holds a persistent Socket.IO WebSocket connection between the victim's browser and the backend, so input is streamed character by character before the form is ever submitted. The operator can watch the entries live, change the page shown to the victim, show notices, and accept, reject or block the entered payment data while the victim stays on the checkout page.
After card capture the victim sees a fake loading or turnstile-style screen and is moved to a counterfeit 3D Secure / bank verification page. Group-IB found 36 financial-institution templates, including app-based verification spoofing, built with a custom OTP/2FA template builder. The OTP the victim types is relayed to the operator, who uses it to authorize the fraudulent transaction before the code expires, or to take over the account. A fake order-confirmation page then delays suspicion.
The operator panel is deployed in Docker containers with an automated installation interface and automatic database/API configuration. It supports multi-account role-based access for affiliates, multi-site management, visitor and conversion tracking, order statistics, configurable card BIN identification and tagging, live keystroke display, session logs of operator-victim interaction, central storage of victim records (cards, personal data, device metadata, fraudulent orders), and browser and Telegram bot notifications. Pricing starts at 300 USDT per month with tiered plans and add-ons, and includes developer support and plugin updates.
Secondary reporting (BankInfoSecurity) adds an annual price of $999, optional 99 USDT/month 'build services' (server configuration, domain registration, WordPress template installation, integration debugging), a companion cloaking service (Cloaked.gg, reported at $1,000+/month) that blocks traffic from cloud providers (AWS, Google Cloud, Azure) and security scanners and shows them decoy pages, a web of proxy addresses used to screen attacks, and victims in Malaysia, Thailand, Singapore, Canada, France, the US and the UK. That reporting also describes reverse-proxy relaying of session cookies; the Group-IB-derived coverage does not mention this, so treat it as lower confidence. Group-IB states that the full IOC list is available only to customers on its Threat Intelligence portal, so no network IOCs (domains, IPs, hashes) are public. The kit has no CVE and no CVSS applies.
MITRE ATT&CK techniques used in TL-2026-2901
Credential Access
T1056.001 Input Capture: Keylogging; T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.002 Proxy: External Proxy
Execution
T1204.001 User Execution: Malicious Link
Defense Evasion
T1480 Execution Guardrails; T1684.001 Impersonation
Initial Access
T1566.003 Phishing: Spearphishing via Service
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.008 Acquire Infrastructure: Malvertising; T1585.001 Establish Accounts: Social Media Accounts
Impact
Affected products and versions in Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses
- Online shoppers / card holders — Payment cards protected by 3D Secure OTP
Vulnerable versions: Customers of 36 impersonated financial institutions - Impersonated retail brands — Brand storefronts (LEGO, Calvin Klein, Aeon Malaysia and 18 other brands)
Vulnerable versions: 21 brands across cosmetics, fashion, food, home and baby, toys and regional supermarkets - Automattic / WooCommerce — WordPress + WooCommerce (abused as phishing storefront platform, not vulnerable)
Remediation for Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses
Immediate actions
- Block or sinkhole lookalike and brand-abusing storefront domains as they are identified; submit takedown requests early, before the pages scale
- Alert on WooCommerce-style checkouts on newly registered domains that open persistent Socket.IO/WebSocket connections to unrelated backends
- Monitor card activity for BIN-clustered small purchases and OTP/3DS challenges that follow merchant checkouts on newly seen merchants
- Report brand-impersonating Facebook and TikTok listings and ads to the platforms
Workarounds
- Shoppers should reach retailers through official apps or manually typed addresses, not social-media ad links
- Treat steep or limited-time discounts as a red flag and check suspect links with urlscan.io, VirusTotal or ScamAdviser
- If card data or an OTP was entered on a suspect store, contact the card issuer immediately, block or replace the card and review transactions
Longer-term hardening
- Move customers to phishing-resistant authentication and app-based transaction confirmation that shows the merchant and amount, rather than OTP codes that can be relayed
- Monitor for social-media and marketplace impersonation of your brand and for malvertising using your brand
- Integrate threat intelligence feeds for PhaaS kit infrastructure into email, web and card-fraud controls
Timeline of Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses
- Kit sold as a subscription PhaaS through Telegram communities from about October 2025, starting at 300 USDT/month with updates and developer support.
- Milk Dragon phishing kit first active (October 2025 per Group-IB); phishing pages begin to be tracked from this month.
- Ongoing from the kit's first appearance: Facebook and TikTok marketplace listings and ads from AI-generated profiles push deep discounts on 21 brands to drive victims to WooCommerce storefronts (exact start date within the period not published).
- Group-IB publishes 'Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy', detailing the BytePress plugin, Socket.IO keystroke streaming and 3DS OTP relay. IOCs are restricted to customers.
- By Group-IB's report, 258 phishing pages are identified across 66 countries, impersonating 21 brands and using 36 financial-institution OTP/3DS templates.
- BankInfoSecurity reports the companion Cloaked.gg scanner-cloaking service, $999 annual plan, 99 USDT/month build services and victims in Malaysia, Thailand, Singapore, Canada, France, the US and the UK.
- Cyber Security News, GBHackers, Cyberpress, BankInfoSecurity and others amplify the Group-IB findings.
Sources cited for Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses
- Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy (Group-IB)
- Milk Dragon AiTM Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA (Cyber Security News)
- Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA (GBHackers)
- Milk Dragon Uses WooCommerce and Malicious WordPress Plugin to Steal Payment Data (Cyberpress)
- Phishing Toolkit Taps Social Media Posts and Advertisements (BankInfoSecurity)
- Phishing Kit Targets Online Shoppers With Fake Discounts (TechJuice)
Detection coverage for TL-2026-2901
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2901 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.