Milk Dragon Phishing Operation Stole Payment Data

The NaiLong phishing kit used social media ads to bypass multi-factor authentication across 66 countries.

Updated on Oct. 2, 2026 in Cybersecurity

Isometric editorial illustration of stacked glass geometric prisms linked by thin wires, symbolizing automated data interception.
The Milk Dragon phishing operation used automated toolkits to capture payment information and bypass multi-factor authentication for users across 66 countries. AI Illustration. Upload story photo >

Live Poll

Do you trust discount advertisements found on social media platforms?

Starting in October 2025, the Milk Dragon phishing operation deployed a kit that captured payment information and intercepted authentication tokens. The campaign utilized social media advertisements to lure global users to fraudulent sites.

Why it matters

The operation demonstrates the vulnerability of standard authentication measures when faced with automated interception toolkits. It highlights how attackers use social media platforms to scale credential harvesting globally.

Group-IB identified 258 distinct phishing pages associated with the Milk Dragon kit since October 2025. This infrastructure facilitates the theft of payment card data and the interception of multi-factor authentication challenges.

The players

Group-IB

A cybersecurity firm specializing in threat intelligence, incident response, and the detection of large-scale financial fraud operations.

The details

The Milk Dragon kit, also identified as NaiLong, employs discount-themed advertisements on platforms like Facebook and TikTok to drive traffic to malicious domains. Once a victim engages with a phishing page, the system operates as a man-in-the-middle, capturing sensitive input while simultaneously intercepting authentication tokens. This mechanism allows the kit to bypass multi-factor authentication—a security layer requiring multiple credentials to verify a user's identity—by facilitating real-time data relay between the user and the legitimate service provider.

Timeline

  1. October 2025: Group-IB first identified the active Milk Dragon phishing kit.

The Tech Race

This activity follows the pattern of sophisticated phishing kits that prioritize bypassing multi-factor authentication as a primary operational goal. It highlights an ongoing race between defensive security protocols and automated interception tools designed for social media scale.

Users interacting with discount-themed advertisements on social media remain primary targets for this credential harvesting method. Protection relies on verifying landing page URLs and avoiding direct financial entry through links originating from unverified social media posts.

The takeaway

The Milk Dragon operation underscores that even enabled multi-factor authentication is vulnerable to real-time token interception. Watch for further threat intelligence disclosures from security firms to identify new signatures of the NaiLong kit.

Further reading

For more on evolving threat landscapes, visit Cybersecurity.

Live Poll

Do you trust discount advertisements found on social media platforms?