Threat reportPhishingTL-2026-2919
Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses (TL-2026-2919), also tracked as Milk Dragon Phishing Kit, is a high-severity phishing campaign, first published 2026-10-04. It is attributed to Milk Dragon with low confidence, affects WordPress WooCommerce checkout (abused by attacker-controlled, maps to 11 MITRE ATT&CK techniques (T1056.001, T1056.003, T1071.001), and is covered by 9 detection rules and 14 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 1Milk Dragon
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-2919
- Threat ID
- TL-2026-2919
- Also known as
- Milk Dragon Phishing Kit, NaiLong Phishing Kit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Milk Dragon
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, ecommerce, consumer goods, financial services, supermarkets
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses
Malware and tooling: Milk Dragon, NaiLong, telegram, WooCommerce
How Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses works
Milk Dragon (aka NaiLong) is a Telegram-sold phishing-as-a-service kit that lures victims with discount-themed Facebook and TikTok posts to counterfeit WordPress/WooCommerce storefronts, harvesting payment card data and relaying 3-D Secure/MFA codes in real time via adversary-in-the-middle bank templates. Group-IB linked 258 phishing pages since October 2025, with victims in 66 countries.
Group-IB (report dated 2026-10-01, covered by GBHackers on 2026-10-02) documents Milk Dragon, also tracked as NaiLong, a phishing-as-a-service (PhaaS) operation active since at least October 2025. The kit is marketed in Telegram communities from 300 USDT per month and includes access to an operator panel, updates, support and role-based accounts. Group-IB identified 258 phishing pages tied to the kit, with victims across 66 countries and 21 impersonated brands spanning cosmetics, fashion, food and beverages, home and baby products, toys and regional supermarket chains (examples named: LEGO, Calvin Klein, Aeon Malaysia).
Distribution relies on native-looking social media posts on Facebook and TikTok that advertise heavily discounted products, supported by fake profiles with AI-generated content and inflated follower counts. A FOMO/discount lure replaces the fear-based pretext of traditional phishing. Clicking through lands the victim on a counterfeit WordPress storefront built on the legitimate WooCommerce plugin.
The core component is a custom malicious WordPress plugin named BytePress (also referenced as the 'SP plugin'). It adds fraudulent payment options (credit card and PayPal) to the WooCommerce checkout, exposes an 'API Base URL' setting that links the site to the operator backend, and holds a persistent Socket.IO WebSocket connection to the operator's server. Victim input is streamed character by character before the form is ever submitted. After card entry the victim sees a fake turnstile/loading screen, then a spoofed 3-D Secure one-time-password page selected from 36 financial-institution templates; the operator can redirect the victim to a different OTP method in real time and relay the code to the legitimate payment processor (adversary-in-the-middle), followed by a fake order-confirmation page.
The operator panel supports a many-to-one multi-domain architecture, role-based subordinate accounts, visitor/order/conversion metrics, card BIN identification with automatic bank tagging, live session monitoring and control, Telegram bot alerts for new submissions, a custom template builder, a central SQL database of victim data with re-targeting profiles, and Docker-containerized deployment with automated setup. Group-IB restricts the full IOC list (domains, IPs, Telegram handles) to its Threat Intelligence portal customers, so no network indicators are publicly disclosed.
MITRE ATT&CK techniques used in TL-2026-2919
Collection
Credential Access
T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle
Command and Control
Execution
Initial Access
T1566.003 Spearphishing via Service
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts
Impact
Defense Evasion
Affected products and versions in Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses
- WordPress — WooCommerce checkout (abused by attacker-controlled storefronts, not a vulnerability)
- Consumers and retail brands — Online shoppers and impersonated brands (e.g. LEGO, Calvin Klein, Aeon Malaysia)
Remediation for Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses
Immediate actions
- Monitor and take down lookalike retail/storefront domains impersonating your brand
- Report fraudulent Facebook and TikTok posts and fake merchant profiles to the platforms
- Flag card-not-present transactions with anomalous checkout patterns and rapid 3-D Secure OTP retries
- Advise customers to notify their bank immediately if card data or OTPs were entered on a suspicious shop
Workarounds
- Hunt for unexpected WordPress plugins (e.g. BytePress) or WooCommerce payment gateways with an 'API Base URL' setting on sites you operate
- Inspect for persistent Socket.IO/WebSocket connections from checkout pages to unfamiliar hosts
Longer-term hardening
- Move payment authentication toward phishing-resistant methods (app-based transaction signing, passkeys) rather than relayable SMS/OTP codes
- Integrate threat intelligence on PhaaS kits and brand-impersonation monitoring
- Educate users that steep social-media discounts are a deception indicator and to verify merchants via urlscan.io, VirusTotal or ScamAdviser
Timeline of Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses
- Earliest activity linked to the Milk Dragon (NaiLong) kit; Group-IB dates the operation to October 2025 (exact day not published, first of month used).
- Group-IB documents the Telegram-sold PhaaS model from 300 USDT/month with operator panel, role-based accounts, BIN tagging, Telegram alerts and Docker deployment.
- Group-IB documents 36 financial-institution 3-D Secure/OTP templates and real-time operator-controlled OTP relay (AiTM).
- Group-IB details the BytePress WordPress plugin: fake WooCommerce card/PayPal payment options, 'API Base URL' operator link, Socket.IO character-by-character keystroke streaming.
- Group-IB publishes its analysis: 258 phishing pages tied to the kit since October 2025, victims in 66 countries, 21 impersonated brands.
- GBHackers on Security reports the Group-IB findings, bringing the campaign to wider defender attention.
- Threadlinqs opens TL-2026-2919 to track the campaign; no public network IOCs available (Group-IB restricts them to portal customers).
Sources cited for Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses
- Group-IB: Milk Dragon (NaiLong) Phishing Kit
- GBHackers: Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
- MITRE ATT&CK T1557 Adversary-in-the-Middle
- MITRE ATT&CK T1111 Multi-Factor Authentication Interception
- MITRE ATT&CK T1566.003 Spearphishing via Service
- MITRE ATT&CK T1056.003 Web Portal Capture
Detection coverage for TL-2026-2919
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2919 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.