Executive Summary
Facts Only
* Victims spanned 66 countries with 258 phishing pages identified since October 2025.
* Phishing pages impersonated brands across industries, including Retail & Supermarket chains like LEGO and Calvin Klein.
* 36 distinct banking templates were used for Adversary-in-the-Middle (AiTM) attacks to bypass Multi-Factor Authentication (MFA).
* Threat actors used native social media posts promoting discounts as phishing lures.
* The Milk Dragon Phishing Kit was sold on Telegram with subscription models ranging from 300 USDT per month for access to panels.
* Phishing pages were hosted on WordPress using WooCommerce and a custom plugin called BytePress.
* The BytePress plugin established a WebSocket connection for real-time command-and-control (C2) communication, streaming victim input directly to the operator.
* The phishing panel featured multi-account management, real-time phishing management, automated notifications, and centralized storage of stolen data.
* Operators could configure card BIN identification across 36 financial institution impersonation templates.
Full Take
The shift in attack methodology reveals a pattern where threat actors are deliberately moving away from high-friction methods (like direct email phishing) toward low-friction, organically integrated social commerce channels to exploit user trust. The core sophistication lies not just in the technical ability to perform AiTM attacks, but in embedding this functionality within a scalable service model (Phishing-as-a-Service) distributed via readily accessible platforms like Telegram. This evolution demonstrates an adaptive strategy: leveraging the inherent trust and engagement found on social media—specifically FOMO-driven retail ads—to make malicious actions feel like routine consumer behavior rather than explicit attacks. The automation provided by tools like Milk Dragon and BytePress allows lower-skilled actors to execute complex, high-volume operations previously requiring significant development resources. This operational scaling lowers the barrier for entry while simultaneously increasing the potential impact of compromised infrastructure across diverse global markets. The implication is that security defenses must move beyond channel-specific monitoring (email/SMS) to encompass the contextual signals present in real-time social and commercial interactions, treating every trusted digital touchpoint as a potential vector for exploitation.
BRIDGE QUESTIONS:
If threat actors are successfully embedding malicious links within legitimate commerce channels, what systemic controls can platforms implement to better distinguish between organic marketing and coordinated malicious distribution? How can organizations effectively monitor the contextual signals of real-time social engagement to detect intent alignment before financial compromise occurs? What new security paradigms must be developed to manage risk when the vector for attack is distributed through trusted consumer interaction rather than traditional threat vectors?
From the original · Group-IB Threat Intelligence
Introduction Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message.Read the full story at group-ib.com
Sentinel — Human
This text reads like an in-depth cybersecurity threat intelligence report, characterized by specific findings, structured analysis, and expert attribution rather than generic content generation.
