A phishing-as-a-service kit called Milk Dragon (also tracked as NaiLong) is using fake discounts on Facebook and TikTok to steal card data and one-time passwords in real time. Group-IB researchers say the kit has been active since October 2025 and has hit victims in 66 countries.
Most phishing relies on fear: a fine, a missed parcel, a bank alert. Milk Dragon relies on the fear of missing out. Operators post native ads and marketplace listings promoting steep discounts on goods people actually want, such as electronics, toys, and supermarket staples.
Because the ads sit inside trusted platforms, users don’t feel targeted. Group-IB has identified 258 phishing pages. They impersonate 21 consumer brands, including LEGO, Calvin Klein and Aeon Malaysia.
Milk Dragon Phishing Kit Uses Fake Facebook, TikTok Deals
Some of the fake profiles pushing the ads appear to use AI-generated content and possibly purchased followers to look legitimate. Researchers could not say whether the operators run these accounts or an underground distribution service does.

Victims who click an ad land on a WordPress site posing as a retailer. The site uses WooCommerce, a legitimate e-commerce plugin, to build its checkout. A custom plugin named BytePress sits alongside it.
It adds fake credit-card and PayPal payment options and links the store to the operator’s command-and-control (C2) server through a field labeled “API Base URL”.
BytePress keeps a persistent socket.io WebSocket connection open to the operator. Everything the victim types is streamed character by character, even if they never press submit. The operator can also push the victim to other pages, accept or block submitted data, and display custom notifications.
After the victim enters card details, a fake loading page buys the operator time. The operator then picks the verification method that matches the victim’s real 3D Secure challenge. The victim enters the OTP on a spoofed page, and the operator relays it to authorize a fraudulent transaction or take over the account. A fake order confirmation then keeps the victim unaware, which delays card cancellation.

Group-IB found 36 banking templates built to capture this MFA data. Affiliates can also build custom verification pages to match a campaign’s region.
The kit is sold on Telegram from 300 USDT per month, with subscription tiers, add-ons, updates, and ongoing support. Buyers supply a server’s IP address, SSH port, and credentials. The installer then deploys a containerized panel through Docker, including the database and API services, potentially in one click.
The panel offers:
- Role-based multi-account management for affiliates and sub-operators.
- Live control of what each victim sees.
- Browser and Telegram bot alerts for victim activity.
- Automatic card tagging by BIN, covering card type and issuing bank.
- Central storage of visitor stats, conversion rates, card data, and device metadata.
The stored data creates reusable victim profiles, so affiliates can re-target people who have already been scammed. One panel can run many phishing sites at once, which lowers the barrier for less-skilled criminals.
Group-IB’s advice for individuals:
- Treat steep or time-limited discounts as a red flag.
- Check unfamiliar shops and ad links with urlscan.io, VirusTotal, or ScamAdviser before entering card details.
- Call your bank or card issuer immediately if you think you’ve been caught.
For enterprises, Group-IB recommends:
- Monitor for lookalike domains and start takedowns early.
- Watch for suspicious card activity and unusual checkout patterns.
- Use threat intelligence to spot new phishing kits early.
Group-IB concludes that email-focused awareness training and MFA alone are no longer enough. Attackers now reach people through social commerce, so verification has to become a habit on every channel.