Group-Ib Milk Dragon Phishing Kit Targets Social Media Discounts to Steal Payment Data
Article Content
- •Milk Dragon phishing kit exploits social media discounts to steal payment data.
- •The operation has affected victims in 66 countries with 258 phishing pages identified.
- •Threat actors use AiTM techniques to bypass MFA protections.
The Milk Dragon phishing kit, also known as NaiLong, is a phishing-as-a-service operation exploiting social media platforms like Facebook and TikTok to lure victims with fake discounts. Group-IB identified 258 phishing pages linked to this kit since October 2025, affecting victims across 66 countries. The kit utilizes Adversary-in-the-Middle (AiTM) techniques to bypass multi-factor authentication (MFA) protections, employing 36 distinct banking templates. Threat actors promote heavily discounted products through native social media posts, driving traffic to fraudulent websites. The Milk Dragon kit has been actively sold on Telegram, with ongoing support provided to affiliates. Major brands, including LEGO and Calvin Klein, have been impersonated to deceive users. The operation has raised significant concerns among cybersecurity analysts and law enforcement agencies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Aeon Malaysia in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How does the Milk Dragon kit operate?
What brands are being impersonated?
What can organizations do to protect against this threat?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…