Threat reportPhishingTL-2026-2919

Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA

highACTIVE

Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses (TL-2026-2919), also tracked as Milk Dragon Phishing Kit, is a high-severity phishing campaign, first published 2026-10-04. It is attributed to Milk Dragon with low confidence, affects WordPress WooCommerce checkout (abused by attacker-controlled, maps to 11 MITRE ATT&CK techniques (T1056.001, T1056.003, T1071.001), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
1Milk Dragon
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-2919

Threat ID
TL-2026-2919
Also known as
Milk Dragon Phishing Kit, NaiLong Phishing Kit
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
Milk Dragon
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
retail, ecommerce, consumer goods, financial services, supermarkets
Target regions
Global
Detection rules
9
Indicators of compromise
14

Malware and tooling in Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses

Malware and tooling: Milk Dragon, NaiLong, telegram, WooCommerce

How Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses works

Milk Dragon (aka NaiLong) is a Telegram-sold phishing-as-a-service kit that lures victims with discount-themed Facebook and TikTok posts to counterfeit WordPress/WooCommerce storefronts, harvesting payment card data and relaying 3-D Secure/MFA codes in real time via adversary-in-the-middle bank templates. Group-IB linked 258 phishing pages since October 2025, with victims in 66 countries.

Group-IB (report dated 2026-10-01, covered by GBHackers on 2026-10-02) documents Milk Dragon, also tracked as NaiLong, a phishing-as-a-service (PhaaS) operation active since at least October 2025. The kit is marketed in Telegram communities from 300 USDT per month and includes access to an operator panel, updates, support and role-based accounts. Group-IB identified 258 phishing pages tied to the kit, with victims across 66 countries and 21 impersonated brands spanning cosmetics, fashion, food and beverages, home and baby products, toys and regional supermarket chains (examples named: LEGO, Calvin Klein, Aeon Malaysia).

Distribution relies on native-looking social media posts on Facebook and TikTok that advertise heavily discounted products, supported by fake profiles with AI-generated content and inflated follower counts. A FOMO/discount lure replaces the fear-based pretext of traditional phishing. Clicking through lands the victim on a counterfeit WordPress storefront built on the legitimate WooCommerce plugin.

The core component is a custom malicious WordPress plugin named BytePress (also referenced as the 'SP plugin'). It adds fraudulent payment options (credit card and PayPal) to the WooCommerce checkout, exposes an 'API Base URL' setting that links the site to the operator backend, and holds a persistent Socket.IO WebSocket connection to the operator's server. Victim input is streamed character by character before the form is ever submitted. After card entry the victim sees a fake turnstile/loading screen, then a spoofed 3-D Secure one-time-password page selected from 36 financial-institution templates; the operator can redirect the victim to a different OTP method in real time and relay the code to the legitimate payment processor (adversary-in-the-middle), followed by a fake order-confirmation page.

The operator panel supports a many-to-one multi-domain architecture, role-based subordinate accounts, visitor/order/conversion metrics, card BIN identification with automatic bank tagging, live session monitoring and control, Telegram bot alerts for new submissions, a custom template builder, a central SQL database of victim data with re-targeting profiles, and Docker-containerized deployment with automated setup. Group-IB restricts the full IOC list (domains, IPs, Telegram handles) to its Threat Intelligence portal customers, so no network indicators are publicly disclosed.

MITRE ATT&CK techniques used in TL-2026-2919

Collection

T1056.001 Keylogging

Credential Access

T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle

Command and Control

T1071.001 Web Protocols

Execution

T1204.001 Malicious Link

Initial Access

T1566.003 Spearphishing via Service

Resource Development

T1583.001 Domains; T1585.001 Social Media Accounts

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses

  • WordPress — WooCommerce checkout (abused by attacker-controlled storefronts, not a vulnerability)
  • Consumers and retail brands — Online shoppers and impersonated brands (e.g. LEGO, Calvin Klein, Aeon Malaysia)

Remediation for Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses

Immediate actions

  • Monitor and take down lookalike retail/storefront domains impersonating your brand
  • Report fraudulent Facebook and TikTok posts and fake merchant profiles to the platforms
  • Flag card-not-present transactions with anomalous checkout patterns and rapid 3-D Secure OTP retries
  • Advise customers to notify their bank immediately if card data or OTPs were entered on a suspicious shop

Workarounds

  • Hunt for unexpected WordPress plugins (e.g. BytePress) or WooCommerce payment gateways with an 'API Base URL' setting on sites you operate
  • Inspect for persistent Socket.IO/WebSocket connections from checkout pages to unfamiliar hosts

Longer-term hardening

  • Move payment authentication toward phishing-resistant methods (app-based transaction signing, passkeys) rather than relayable SMS/OTP codes
  • Integrate threat intelligence on PhaaS kits and brand-impersonation monitoring
  • Educate users that steep social-media discounts are a deception indicator and to verify merchants via urlscan.io, VirusTotal or ScamAdviser

Timeline of Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses

  • Earliest activity linked to the Milk Dragon (NaiLong) kit; Group-IB dates the operation to October 2025 (exact day not published, first of month used).
  • Group-IB documents the Telegram-sold PhaaS model from 300 USDT/month with operator panel, role-based accounts, BIN tagging, Telegram alerts and Docker deployment.
  • Group-IB documents 36 financial-institution 3-D Secure/OTP templates and real-time operator-controlled OTP relay (AiTM).
  • Group-IB details the BytePress WordPress plugin: fake WooCommerce card/PayPal payment options, 'API Base URL' operator link, Socket.IO character-by-character keystroke streaming.
  • Group-IB publishes its analysis: 258 phishing pages tied to the kit since October 2025, victims in 66 countries, 21 impersonated brands.
  • GBHackers on Security reports the Group-IB findings, bringing the campaign to wider defender attention.
  • Threadlinqs opens TL-2026-2919 to track the campaign; no public network IOCs available (Group-IB restricts them to portal customers).

Sources cited for Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses

Detection coverage for TL-2026-2919

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2919 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats