Milk Dragon Phishing Service Exploits Social‑Media Discount Ads to Hijack Cards and MFA
A cyber‑crime outfit operating under the name Milk Dragon, also referred to as NaiLong, has been caught running a phishing‑as‑a‑service scheme that leverages seemingly harmless discount promotions on Facebook and TikTok to pilfer payment‑card details and intercept multi‑factor authentication challenges.
The group creates short‑form videos and sponsored posts that promise limited‑time coupons or price cuts on popular consumer goods. When users click the embedded links, they are redirected to counterfeit checkout pages that look identical to legitimate merchant sites. Those pages capture the victim's credit‑card number, expiration date and security code before forwarding the transaction to the real retailer.
What sets Milk Dragon apart from typical card‑skimming operations is its ability to seize the one‑time passcodes generated by MFA systems. After the victim submits card information, the fake site triggers a verification request—often via SMS or an authenticator app. The phishing kit then relays that request to a separate server controlled by the attackers, allowing them to enter the code and complete the purchase without the user’s knowledge.
Cyber‑security firm Group‑IB reported that it has catalogued 258 distinct phishing pages linked to the Milk Dragon kit since the campaign’s emergence. The pages span a variety of e‑commerce niches, from fashion accessories to electronics, and are hosted on disposable domains that rotate to evade takedown efforts. Group‑IB’s analysis indicates that the kit is sold to other criminal actors as a ready‑made service, complete with templates, hosting instructions and instructions for capturing MFA tokens.
Experts warn that the blend of social‑media marketing tactics with sophisticated MFA interception could broaden the attack surface for both consumers and businesses. Security professionals recommend that users treat any discount offer that arrives via a social platform with suspicion, verify URLs before entering sensitive data, and consider using hardware‑based authentication methods that are less vulnerable to relay attacks. Meanwhile, investigators continue to track the infrastructure behind Milk Dragon, hoping to dismantle the service and curb its spread across the underground cyber‑crime market.
Comments (0)
Be the first to comment.
Join the discussion