Milk Dragon phishing campaign targets 66 countries with fake ecommerce sites to steal payment data

Published:

Security researchers from Group-IB have uncovered a widespread phishing campaign dubbed “Milk Dragon,” which targets victims across 66 countries through fake e-commerce sites and social media promotions. This campaign exploits trusted brands like Lego and Calvin Klein, luring users with enticing discounts that ultimately lead to the theft of payment data.

For over a year, the Milk Dragon group has utilized a phishing kit to create counterfeit versions of popular online shopping platforms, sometimes employing artificial intelligence to generate entirely fictitious product listings. The campaign primarily operates through social media channels, particularly Facebook and TikTok, where users seeking bargains are more likely to engage with the fraudulent posts.

Phishing Tactics and Malware Behavior

The Milk Dragon campaign distinguishes itself by leveraging social media to distribute its phishing lures, a shift from traditional email-based tactics. Group-IB’s report highlights that this method circumvents the improved spam filters of email providers, allowing the attackers to reach potential victims more effectively.

The fraudulent websites are equipped with a malware known as BytePress, which captures user input in real-time, even before the information is submitted. This capability allows the malware to stream keystrokes directly to the attackers’ command-and-control infrastructure, effectively bypassing any multi-factor authentication (MFA) measures victims may have in place. When victims enter their credentials, the malware relays the information to the legitimate site, including any MFA requests, which are then intercepted by the attackers.

Global Reach and Targeted Brands

The Milk Dragon campaign has cast a wide net, affecting victims in numerous countries, with the highest numbers reported in Malaysia, Singapore, and Thailand. The group has spoofed a total of 21 well-known brands across various sectors, including cosmetics, fashion, food, and banking, indicating a broad strategy aimed at maximizing potential targets.

Interestingly, the Milk Dragon phishing kit is available for purchase on Telegram, where various hacking groups can subscribe to its services for a fee, further indicating the commercial nature of this cybercrime operation. Subscription plans start at 300 USDT per month, allowing other criminals to leverage the kit for their own phishing endeavors.

As the Milk Dragon campaign continues to evolve, it underscores the importance of vigilance among consumers, particularly when encountering deals that seem too good to be true. Users are advised to verify the authenticity of offers and to remain cautious when sharing personal information online.

For further insights into the tactics employed by this campaign and the broader implications for online security, refer to the detailed analysis by Group-IB.

TechRadar

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike enhances Falcon Cloud Security with AI-driven third-party application insights for risk management

CrowdStrike has announced significant enhancements to its Falcon Cloud Security platform, introducing AI-driven insights into third-party applications that aim to bolster risk management for...

AI agents in the Middle East require human oversight and cultural understanding, says TP Group’s COO

Augusto Martinez Reyes, COO EMEA and President of Multilingual Hubs at TP Group, emphasized the necessity for human oversight in the deployment of AI...

Microsoft issues urgent security updates for CVE-2026-96940 flaw in Exchange Server allowing mailbox access

Microsoft has issued urgent out-of-band security updates to address a critical vulnerability in Microsoft Exchange Server, identified as CVE-2026-96940, which has been rated 8.8...

Astroscale U.S. plans 2026 launch of Provisioner® spacecraft to demonstrate on-orbit refueling for missile defense systems

Astroscale U.S. is set to launch its Provisioner® spacecraft in 2026, aiming to demonstrate on-orbit refueling capabilities that could significantly enhance missile defense systems....