# Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA

> Milk Dragon (aka NaiLong) is a Telegram-sold phishing-as-a-service kit that lures victims with discount-themed Facebook and TikTok posts to counterfeit WordPress/WooCommerce storefronts, harvesting payment card data and relaying 3-D Secure/MFA codes in real time via adversary-in-the-middle bank templates. Group-IB linked 258 phishing pages since October 2025, with victims in 66 countries.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2919
- **ID:** TL-2026-2919
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Milk Dragon
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Group-IB (report dated 2026-10-01, covered by GBHackers on 2026-10-02) documents Milk Dragon, also tracked as NaiLong, a phishing-as-a-service (PhaaS) operation active since at least October 2025. The kit is marketed in Telegram communities from 300 USDT per month and includes access to an operator panel, updates, support and role-based accounts. Group-IB identified 258 phishing pages tied to the kit, with victims across 66 countries and 21 impersonated brands spanning cosmetics, fashion, food and beverages, home and baby products, toys and regional supermarket chains (examples named: LEGO, Calvin Klein, Aeon Malaysia).

Distribution relies on native-looking social media posts on Facebook and TikTok that advertise heavily discounted products, supported by fake profiles with AI-generated content and inflated follower counts. A FOMO/discount lure replaces the fear-based pretext of traditional phishing. Clicking through lands the victim on a counterfeit WordPress storefront built on the legitimate WooCommerce plugin.

The core component is a custom malicious WordPress plugin named BytePress (also referenced as the 'SP plugin'). It adds fraudulent payment options (credit card and PayPal) to the WooCommerce checkout, exposes an 'API Base URL' setting that links the site to the operator backend, and holds a persistent Socket.IO WebSocket connection to the operator's server. Victim input is streamed character by character before the form is ever submitted. After card entry the victim sees a fake turnstile/loading screen, then a spoofed 3-D Secure one-time-password page selected from 36 financial-institution templates; the operator can redirect the victim to a different OTP method in real time and relay the code to the legitimate payment processor (adversary-in-the-middle), followed by a fake order-confirmation page.

The operator panel supports a many-to-one multi-domain architecture, role-based subordinate accounts, visitor/order/conversion metrics, card BIN identification with automatic bank tagging, live session monitoring and control, Telegram bot alerts for new submissions, a custom template builder, a central SQL database of victim data with re-targeting profiles, and Docker-containerized deployment with automated setup. Group-IB restricts the full IOC list (domains, IPs, Telegram handles) to its Threat Intelligence portal customers, so no network indicators are publicly disclosed.

## MITRE ATT&CK

- T1583.001 Domains
- T1585.001 Social Media Accounts
- T1566.003 Spearphishing via Service
- T1204.001 Malicious Link
- T1684.001 Impersonation
- T1557 Adversary-in-the-Middle
- T1111 Multi-Factor Authentication Interception
- T1056.003 Web Portal Capture
- T1056.001 Keylogging
- T1071.001 Web Protocols
- T1657 Financial Theft

## Sources

- [Group-IB: Milk Dragon (NaiLong) Phishing Kit](https://www.group-ib.com/blog/milk-dragon-nailong-phishing-kit/)
- [GBHackers: Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA](https://gbhackers.com/milk-dragon-phishing-kit/)
- [MITRE ATT&CK T1557 Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557/)
- [MITRE ATT&CK T1111 Multi-Factor Authentication Interception](https://attack.mitre.org/techniques/T1111/)
- [MITRE ATT&CK T1566.003 Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003/)
- [MITRE ATT&CK T1056.003 Web Portal Capture](https://attack.mitre.org/techniques/T1056/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2919
