# Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA

> Milk Dragon (aka NaiLong) is a subscription phishing-as-a-service kit, active since October 2025, that runs card-fraud storefronts on WordPress/WooCommerce and relays 3D Secure OTPs to operators in real time. Group-IB identified 258 phishing pages across 66 countries, 36 financial-institution OTP templates and 21 impersonated brands.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2901
- **ID:** TL-2026-2901
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Milk Dragon
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Group-IB (published 2026-10-01) describes Milk Dragon, also tracked as NaiLong, a Telegram-sold phishing-as-a-service (PhaaS) kit that has been active since at least October 2025. Victims are lured by Facebook and TikTok marketplace listings and ads, posted from AI-generated profiles with purchased follower bases, offering steep discounts on well-known brands (examples named: LEGO, Calvin Klein, Aeon Malaysia; 21 brands in total across cosmetics, fashion, food and beverage, home and baby products, toys and regional supermarket chains). The lure leans on fear of missing out on a bargain rather than the fear or urgency used by classic phishing, and the traffic arrives from ordinary-looking social ads, which lowers suspicion.

The landing sites are WordPress stores running WooCommerce. A custom malicious plugin, BytePress (also referred to as the 'SP plugin'), adds fraudulent card and PayPal payment options to the WooCommerce checkout and acts as the C2 and operator-control component. The operator enters the address of their C2 panel in a plugin settings field labelled 'API Base URL'. BytePress then holds a persistent Socket.IO WebSocket connection between the victim's browser and the backend, so input is streamed character by character before the form is ever submitted. The operator can watch the entries live, change the page shown to the victim, show notices, and accept, reject or block the entered payment data while the victim stays on the checkout page.

After card capture the victim sees a fake loading or turnstile-style screen and is moved to a counterfeit 3D Secure / bank verification page. Group-IB found 36 financial-institution templates, including app-based verification spoofing, built with a custom OTP/2FA template builder. The OTP the victim types is relayed to the operator, who uses it to authorize the fraudulent transaction before the code expires, or to take over the account. A fake order-confirmation page then delays suspicion.

The operator panel is deployed in Docker containers with an automated installation interface and automatic database/API configuration. It supports multi-account role-based access for affiliates, multi-site management, visitor and conversion tracking, order statistics, configurable card BIN identification and tagging, live keystroke display, session logs of operator-victim interaction, central storage of victim records (cards, personal data, device metadata, fraudulent orders), and browser and Telegram bot notifications. Pricing starts at 300 USDT per month with tiered plans and add-ons, and includes developer support and plugin updates.

Secondary reporting (BankInfoSecurity) adds an annual price of $999, optional 99 USDT/month 'build services' (server configuration, domain registration, WordPress template installation, integration debugging), a companion cloaking service (Cloaked.gg, reported at $1,000+/month) that blocks traffic from cloud providers (AWS, Google Cloud, Azure) and security scanners and shows them decoy pages, a web of proxy addresses used to screen attacks, and victims in Malaysia, Thailand, Singapore, Canada, France, the US and the UK. That reporting also describes reverse-proxy relaying of session cookies; the Group-IB-derived coverage does not mention this, so treat it as lower confidence. Group-IB states that the full IOC list is available only to customers on its Threat Intelligence portal, so no network IOCs (domains, IPs, hashes) are public. The kit has no CVE and no CVSS applies.

## MITRE ATT&CK

- T1583.008 Acquire Infrastructure: Malvertising
- T1583.001 Acquire Infrastructure: Domains
- T1585.001 Establish Accounts: Social Media Accounts
- T1566.003 Phishing: Spearphishing via Service
- T1204.001 User Execution: Malicious Link
- T1684.001 Impersonation
- T1480 Execution Guardrails
- T1056.001 Input Capture: Keylogging
- T1056.003 Input Capture: Web Portal Capture
- T1111 Multi-Factor Authentication Interception
- T1071.001 Application Layer Protocol: Web Protocols
- T1090.002 Proxy: External Proxy
- T1657 Financial Theft

## Sources

- [Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy (Group-IB)](https://www.group-ib.com/blog/milk-dragon-nailong-phishing-kit/)
- [Milk Dragon AiTM Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA (Cyber Security News)](https://cybersecuritynews.com/milk-dragon-aitm-kit/)
- [Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA (GBHackers)](https://gbhackers.com/milk-dragon-phishing-kit/)
- [Milk Dragon Uses WooCommerce and Malicious WordPress Plugin to Steal Payment Data (Cyberpress)](https://cyberpress.org/milk-dragon-targets-woocommerce/)
- [Phishing Toolkit Taps Social Media Posts and Advertisements (BankInfoSecurity)](https://www.bankinfosecurity.com/phishing-toolkit-taps-social-media-posts-advertisements-a-33006)
- [Phishing Kit Targets Online Shoppers With Fake Discounts (TechJuice)](https://www.techjuice.pk/milk-dragon-phishing-kit-targets-shoppers-66-countries/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2901
