Milk Dragon AiTM Kit Bypasses MFA With Real-Time OTP Relay and WebSocket Keylogging
Key Takeaways The “Milk Dragon” (also known as “NaiLong”) phishing kit is actively defrauding online shoppers globally. It leverages fake retail offers on social media and...
Key Takeaways
- The “Milk Dragon” (also known as “NaiLong”) phishing kit is actively defrauding online shoppers globally.
- It leverages fake retail offers on social media and marketplaces to direct victims to convincing, malicious e-commerce sites.
- The kit employs a sophisticated real-time attack-in-the-middle (AiTM) technique, including WebSocket keylogging and OTP relay, to bypass multi-factor authentication (MFA) and steal payment credentials.
- This phishing-as-a-service (PhaaS) offering is sold via Telegram, making advanced fraud accessible to a wider range of threat actors.
Sophisticated Milk Dragon Phishing Kit Bypasses MFA with Real-Time Data Relay
A new, highly effective phishing kit named “Milk Dragon,” also identified as “NaiLong,” has been operating since October 2025, specializing in payment fraud by luring unsuspecting shoppers with enticing online deals. Unlike traditional phishing schemes that rely on alarmist emails, this campaign embeds malicious links within legitimate-looking marketplace advertisements and social media posts, leveraging the allure of steep discounts to ensnare victims.
Table Of Content
Upon clicking these deceptive offers, users are redirected to fraudulent online stores designed to mimic genuine retailers. These sites then prompt for sensitive information, including credit card details, personal data, and payment verification, all under the guise of a legitimate transaction.
Researchers at Group-IB said in a report that they have tracked Milk Dragon’s activities across 66 countries, identifying 258 unique phishing pages and 36 distinct financial institution verification templates since its inception. The widespread nature of this operation is largely attributed to its availability as a subscription service through Telegram communities, significantly lowering the barrier for entry for cybercriminals to launch sophisticated fraud campaigns.
Group-IB further noted that the Milk Dragon kit is available for as little as 300 USDT per month, providing operators with ongoing updates and support for their phishing infrastructure.
Inside the Milk Dragon AiTM Kit
The attack vector for Milk Dragon typically begins with advertisements promoting unusually low prices on a wide array of products, from electronics and toys to fashion and everyday supermarket items. These promotional posts often originate from accounts that employ AI-generated content or purchased followers to cultivate a false sense of trustworthiness, turning casual browsing into a potentially devastating fraud session for unsuspecting consumers.
Once a victim clicks on a malicious advertisement, they are directed to a WordPress-based website meticulously crafted to resemble a legitimate e-commerce platform. While these sites often utilize WooCommerce for their checkout process, a custom malicious plugin, dubbed “BytePress,” is integrated. This plugin introduces fake payment options, such as counterfeit credit card and PayPal gateways, and establishes a connection to a backend panel controlled by the threat actor.
A critical component of BytePress is its persistent Socket.IO WebSocket connection, which maintains a live link between the victim’s browser and the criminal’s server. This real-time connection grants the operator granular control over the victim’s session, allowing them to dynamically alter pages, display custom notices, and manipulate the acceptance or rejection of entered payment data while the victim remains on the checkout screen.
Crucially, this WebSocket connection facilitates real-time keylogging, streaming every character typed by the victim, even before a form is officially submitted. This advanced capability mirrors techniques seen in live payment page fraud, enabling criminals to monitor and capture sensitive information, including credit card numbers and one-time passwords (OTPs), as they are entered.
Following the submission of payment details, Milk Dragon displays a fabricated loading screen before redirecting the victim to a counterfeit verification page. Here, the operator selects a template that matches the authentication request from the legitimate 3D Secure payment system. This allows the threat actor to capture and relay the one-time password provided by the victim, thereby authorizing fraudulent transactions or facilitating account takeover.
Social Commerce Lures Amplify Fraud Risk
The effectiveness of Milk Dragon lies in its exploitation of social commerce trends, where users often engage with content casually and may not anticipate fraudulent activities stemming from advertisements. The campaign frames its offers around a “fear of missing out” (FOMO) rather than employing the urgent tones characteristic of traditional phishing, making them appear as genuine shopping opportunities.
The operator’s control panel is a centralized hub for managing visitor data, card records, order details, and campaign statistics. It supports the deployment of multiple phishing pages from a single backend, offers role-based accounts for different operators, and provides notifications via browser or Telegram.
The kit’s reliance on reusable templates enables criminals to easily adapt the same fraudulent workflow for various geographical regions and financial institutions. This trend highlights a broader shift towards PhaaS kits that specialize in real-time authentication relay, a more advanced technique compared to simply harvesting static passwords.
Milk Dragon exemplifies the dangerous combination of social commerce lures with operator-driven credential capture. While specific indicators of compromise (IoCs) for this campaign have not been publicly disclosed, its operational model underscores the evolving landscape of online fraud.
What You Should Do
- Exercise Extreme Caution: Treat exceptionally low prices or unfamiliar online shops advertised on social media and marketplaces as potential warning signs.
- Verify Retailers Independently: Before entering any payment information, independently verify the legitimacy of the retailer by visiting their official website directly, rather than clicking links in advertisements. Utilize trusted reputation services to check the authenticity of links.
- Monitor Financial Accounts: Regularly review bank and credit card statements for any unauthorized transactions.
- Report Suspicious Activity: If you suspect you have fallen victim to Milk Dragon or a similar scam, immediately contact your bank or credit card provider and report the fraudulent activity.
- Implement Phishing-Resistant MFA: For organizations, deploy phishing-resistant multi-factor authentication (MFA) methods that are not susceptible to OTP relay attacks, reducing the value of stolen credentials.
- Educate Users: Conduct regular training for employees and users on recognizing social media shopping scams, RCS/iMessage phishing, and the importance of verifying links and retailers.
- Monitor for Lookalike Domains: Organizations should actively monitor for lookalike domains and suspicious checkout patterns, initiating takedown procedures promptly to mitigate campaign expansion.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.