Skip to content

Executive Summary

Threat actors utilize a phishing kit named Milk Dragon to distribute fraudulent links by leveraging social media advertisements, specifically in e-commerce listings on platforms like Facebook and TikTok, rather than traditional email methods. This method targets victims using Fear of Missing Out (FOMO) through fake, heavily discounted offers on popular brands. The phishing workflow redirects victims from these lures to WordPress sites utilizing WooCommerce for checkout, augmented by a custom plugin called BytePress for command-and-control (C2) communication. This setup employs an Adversary-in-the-Middle (AiTM) technique, using banking templates and 3D Secure bypasses to capture credentials in real-time. Operators manage these large-scale campaigns through a centralized Milk Dragon phishing panel, which allows for multi-account management, real-time session manipulation via the BytePress plugin, and centralized storage of harvested data, including payment details.

Facts Only

* Victims spanned 66 countries with 258 phishing pages identified since October 2025.
* Phishing pages impersonated brands across industries, including Retail & Supermarket chains like LEGO and Calvin Klein.
* 36 distinct banking templates were used for Adversary-in-the-Middle (AiTM) attacks to bypass Multi-Factor Authentication (MFA).
* Threat actors used native social media posts promoting discounts as phishing lures.
* The Milk Dragon Phishing Kit was sold on Telegram with subscription models ranging from 300 USDT per month for access to panels.
* Phishing pages were hosted on WordPress using WooCommerce and a custom plugin called BytePress.
* The BytePress plugin established a WebSocket connection for real-time command-and-control (C2) communication, streaming victim input directly to the operator.
* The phishing panel featured multi-account management, real-time phishing management, automated notifications, and centralized storage of stolen data.
* Operators could configure card BIN identification across 36 financial institution impersonation templates.

Full Take

The shift in attack methodology reveals a pattern where threat actors are deliberately moving away from high-friction methods (like direct email phishing) toward low-friction, organically integrated social commerce channels to exploit user trust. The core sophistication lies not just in the technical ability to perform AiTM attacks, but in embedding this functionality within a scalable service model (Phishing-as-a-Service) distributed via readily accessible platforms like Telegram. This evolution demonstrates an adaptive strategy: leveraging the inherent trust and engagement found on social media—specifically FOMO-driven retail ads—to make malicious actions feel like routine consumer behavior rather than explicit attacks. The automation provided by tools like Milk Dragon and BytePress allows lower-skilled actors to execute complex, high-volume operations previously requiring significant development resources. This operational scaling lowers the barrier for entry while simultaneously increasing the potential impact of compromised infrastructure across diverse global markets. The implication is that security defenses must move beyond channel-specific monitoring (email/SMS) to encompass the contextual signals present in real-time social and commercial interactions, treating every trusted digital touchpoint as a potential vector for exploitation.
BRIDGE QUESTIONS:
If threat actors are successfully embedding malicious links within legitimate commerce channels, what systemic controls can platforms implement to better distinguish between organic marketing and coordinated malicious distribution? How can organizations effectively monitor the contextual signals of real-time social engagement to detect intent alignment before financial compromise occurs? What new security paradigms must be developed to manage risk when the vector for attack is distributed through trusted consumer interaction rather than traditional threat vectors?

From the original · Group-IB Threat Intelligence

Introduction Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message.
Read the full story at group-ib.com

Sentinel — Human

Confidence

This text reads like an in-depth cybersecurity threat intelligence report, characterized by specific findings, structured analysis, and expert attribution rather than generic content generation.

Signals Detected
low severity: Sentence length variance exhibits natural variation; vocabulary is technical but flows contextually.
low severity: The text presents a clear, structured narrative arc typical of threat intelligence reporting, maintaining internal consistency.
low severity: Attribution to 'Group-IB' and detailed breakdown of technical mechanisms suggests a source rooted in investigative reporting, not pure generative synthesis.
low severity: The heavy reliance on specific, granular attack details (e.g., BytePress plugin functionality, 36 banking templates) points toward internal analysis rather than generalized LLM fabrication.
Human Indicators
Use of specific, attributed research context (Group-IB portal references), highly technical jargon woven into a narrative flow, and the defensive/investigative tone strongly suggest human analyst writing.
The concluding recommendations are actionable advice typical of threat intelligence reports.
Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy | Huntaegis