Security researchers from Group-IB have uncovered a widespread phishing campaign dubbed “Milk Dragon,” which targets victims across 66 countries through fake e-commerce sites and social media promotions. This campaign exploits trusted brands like Lego and Calvin Klein, luring users with enticing discounts that ultimately lead to the theft of payment data.
For over a year, the Milk Dragon group has utilized a phishing kit to create counterfeit versions of popular online shopping platforms, sometimes employing artificial intelligence to generate entirely fictitious product listings. The campaign primarily operates through social media channels, particularly Facebook and TikTok, where users seeking bargains are more likely to engage with the fraudulent posts.
Phishing Tactics and Malware Behavior
The Milk Dragon campaign distinguishes itself by leveraging social media to distribute its phishing lures, a shift from traditional email-based tactics. Group-IB’s report highlights that this method circumvents the improved spam filters of email providers, allowing the attackers to reach potential victims more effectively.
The fraudulent websites are equipped with a malware known as BytePress, which captures user input in real-time, even before the information is submitted. This capability allows the malware to stream keystrokes directly to the attackers’ command-and-control infrastructure, effectively bypassing any multi-factor authentication (MFA) measures victims may have in place. When victims enter their credentials, the malware relays the information to the legitimate site, including any MFA requests, which are then intercepted by the attackers.
Global Reach and Targeted Brands
The Milk Dragon campaign has cast a wide net, affecting victims in numerous countries, with the highest numbers reported in Malaysia, Singapore, and Thailand. The group has spoofed a total of 21 well-known brands across various sectors, including cosmetics, fashion, food, and banking, indicating a broad strategy aimed at maximizing potential targets.
Interestingly, the Milk Dragon phishing kit is available for purchase on Telegram, where various hacking groups can subscribe to its services for a fee, further indicating the commercial nature of this cybercrime operation. Subscription plans start at 300 USDT per month, allowing other criminals to leverage the kit for their own phishing endeavors.
As the Milk Dragon campaign continues to evolve, it underscores the importance of vigilance among consumers, particularly when encountering deals that seem too good to be true. Users are advised to verify the authenticity of offers and to remain cautious when sharing personal information online.
For further insights into the tactics employed by this campaign and the broader implications for online security, refer to the detailed analysis by Group-IB.


