How does the Milk Dragon phishing scam operate?
The Milk Dragon phishing scam functions by intercepting users through highly convincing social media advertisements that promise massive discounts on well-known global brands. Instead of traditional email-based phishing, which is increasingly blocked by advanced spam filters, this threat actor targets users within specific social media groups and pages where bargain hunters congregate. By using platforms like TikTok and Facebook, the attackers meet potential victims in environments where they are already looking for deals, lowering their natural suspicion.
According to Group-IB, the attackers have been active for at least a year, utilizing a specialized phishing kit to create fraudulent versions of popular ecommerce websites. To increase the legitimacy of these fake stores, the group has even been observed using artificial intelligence to generate entirely fabricated product listings. This combination of social engineering and AI-driven content makes the lures exceptionally difficult for the average consumer to distinguish from genuine promotional posts.
The shift from email to social media lures
Historically, phishing campaigns relied heavily on email delivery. However, as email service providers have implemented more robust filtering technologies, threat actors have migrated to social media. This shift allows them to bypass traditional security perimeters and engage with users in a more personal, community-driven context, such as Facebook groups dedicated to shopping discounts.
What makes the BytePress malware so dangerous?
The BytePress malware is the technical engine behind the Milk Dragon campaign, designed to capture data with unprecedented precision. Unlike standard phishing kits that wait for a user to click a 'submit' button, BytePress is capable of streaming information character by character as it is typed. This means that even if a victim realizes something is wrong and closes the browser before submitting the form, their credentials and payment details may have already been intercepted.
This real-time data streaming capability allows the attackers to maintain a constant flow of information to their command-and-control panels. The malware effectively turns the victim's own input device into a tool for the attacker, ensuring that almost every keystroke related to sensitive data is recorded and transmitted instantly.
Defeating multi-factor authentication (MFA)
One of the most sophisticated aspects of the BytePress malware is its ability to bypass multi-factor authentication. When a victim enters their details, the malware relays the information to the legitimate website in the background. The real site then issues a request for a one-time password (OTP) or MFA code, which is sent back to the victim. The malware intercepts this code and immediately passes it to the attackers, allowing them to complete the unauthorized transaction or account takeover seamlessly.
How do attackers hide their tracks from victims?
The Milk Dragon group employs a psychological tactic known as 'buying time' to prevent victims from realizing they have been defrauded. Once the stolen data has been successfully captured and the MFA codes intercepted, the fake ecommerce site displays a fraudulent order confirmation page. This page mimics a successful transaction, leading the victim to believe their purchase was processed correctly.
By providing this false sense of security, the attackers ensure that the victim does not immediately contact their bank or attempt to freeze their credit cards. This delay is critical for the criminals, as it gives them a window of opportunity to use the stolen credentials for various malicious purposes before the fraud is detected and reported. The longer the victim believes the transaction was legitimate, the more damage the attackers can inflict.
What is the global scale and target of this campaign?
The Milk Dragon campaign has demonstrated a massive global reach, with victims identified in 66 different countries. While the group does not appear to target a specific nationality, the concentration of victims suggests certain regional vulnerabilities or successful targeting of specific social media demographics. According to Group-IB, the highest number of victims were located in Southeast Asia, specifically in Malaysia (over 1,300 victims), Singapore (over 1,200 victims), and Thailand (over 1,100 victims).
The scope of the impersonation is also remarkably broad. The attackers have spoofed 21 different popular brands across multiple industries, including fashion, cosmetics, food and beverages, and toys. Furthermore, the campaign frequently targets regional supermarkets and has successfully impersonated 36 different financial institutions and banks, highlighting the diverse range of sectors the group is willing to exploit to gain trust.
How is the Milk Dragon phishing kit distributed?
The infrastructure supporting these attacks is available to a wider criminal ecosystem through 'Phishing-as-a-Service' (PhaaS) models. The Milk Dragon phishing kit is actively sold on Telegram channels, allowing various hacking groups to subscribe to the service. This lowers the barrier to entry for cybercriminals, as they do not need to develop their own malware or spoofing tools; they simply pay for access to a ready-made kit.
Subscription models for the kit are priced competitively within the criminal market. According to the Group-IB report, the service starts at 300 USDT (Tether) per month. Various subscription tiers and add-ons are available, allowing attackers to customize the kit to their specific needs, whether they want to target specific brands or deploy more advanced features of the BytePress malware.
Frequently asked questions
How can I tell if a social media discount is a scam?
Be extremely cautious of deals that seem too good to be true, especially on platforms like Facebook or TikTok. Always verify the discount by visiting the brand's official website directly through your browser rather than clicking links provided in social media posts or group messages.
Can multi-factor authentication protect me from BytePress?
Standard multi-factor authentication may not be enough against BytePress, as the malware is designed to intercept MFA codes in real-time. Using hardware-based security keys that require physical interaction can provide a much higher level of protection against this specific type of real-time interception.
What should I do if I think I have been a victim?
Immediately contact your bank or credit card issuer to freeze your accounts and report the fraudulent activity. You should also change your passwords for any accounts that may have been compromised and monitor your financial statements closely for any further unauthorized transactions.
Is my data safe if I don't click 'submit' on a fake site?
Not necessarily. Because the BytePress malware can stream keystrokes in real-time, your information may be captured as you type it. It is vital to avoid entering any sensitive data into suspicious websites, even if you intend to close the page before finishing the form.
Why are attackers using social media instead of email?
Attackers use social media because email security filters have become highly effective at catching phishing attempts. Social media groups provide a less regulated environment where attackers can build trust and reach large numbers of people who are actively looking for bargains.
Key takeaways
- The Milk Dragon group uses fake social media posts to lure victims into phishing sites.
- BytePress malware captures keystrokes in real-time, even before a user clicks submit.
- The campaign has successfully bypassed MFA by intercepting one-time passwords.
- Over 1,300 victims were identified in Malaysia, with high numbers in Singapore and Thailand.
- The phishing kit is sold on Telegram starting at 300 USDT per month.
Conclusion
The Milk Dragon phishing campaign represents a sophisticated evolution in social engineering, moving away from predictable email lures toward more integrated social media deception. By combining AI-generated content, real-time keystroke logging via BytePress, and MFA interception, these attackers have created a highly effective pipeline for stealing financial data. As the group continues to offer its services via Telegram, the threat of widespread ecommerce fraud remains high. Consumers must remain vigilant, treating unsolicited social media deals with extreme skepticism and prioritizing direct, official channels for all online shopping activities to mitigate the risk of falling victim to these advanced phishing tactics.
