Milk Dragon AiTM Kit Leverages Real-Time Keylogging and OTP Relay to Bypass MFA
The 'Milk Dragon' phishing kit, active since October 2025, uses a custom WordPress plugin to enable real-time keylogging and one-time password relay, effectively bypassing multi-factor authentication for financial fraud.

A sophisticated phishing kit known as 'Milk Dragon,' also referred to as 'NaiLong,' has been actively targeting online shoppers since October 2025. This operation employs deceptive retail offers disseminated through social media and online marketplaces to lure unsuspecting victims into fraudulent checkout pages. Unlike traditional phishing campaigns that rely on urgent emails or delivery alerts, Milk Dragon leverages enticing discounts on everyday goods, electronics, and fashion to draw users in.
Researchers from Group-IB have identified a significant global footprint for this operation, with 258 phishing pages detected across 66 countries. The kit's effectiveness is amplified by its distribution as a subscription service within Telegram communities, lowering the barrier to entry for cybercriminals. The service reportedly starts at 300 USDT per month and includes ongoing support and updates for the phishing infrastructure.
The attack chain begins with advertisements showcasing unusually low prices, often posted from accounts that may use AI-generated content or purchased followers to appear legitimate. Once a victim clicks on a suspicious link, they are directed to a fake retail website built on WordPress and utilizing WooCommerce for its checkout process. However, a malicious custom plugin named 'BytePress' injects counterfeit payment options, including fake card and PayPal choices, and establishes a persistent Socket.IO WebSocket connection to an operator-controlled backend.
This real-time WebSocket connection is central to Milk Dragon's advanced evasion techniques. It allows the operator to dynamically alter pages, display custom notifications, and crucially, monitor and intercept payment data as the victim enters it, even before a form is submitted. This capability mirrors the threat of live payment page fraud, where criminals can observe sensitive details as they are typed.
Following the entry of payment details, the kit presents a fake loading screen before redirecting the victim to a counterfeit verification page. The attacker then selects a template that mimics the legitimate 3D Secure payment authentication request, capturing and relaying the one-time password (OTP) to authorize fraudulent transactions or compromise accounts. This method directly targets and bypasses multi-factor authentication mechanisms.
The campaign's reliance on social commerce lures exploits the casual browsing habits of users on social platforms, making them less likely to suspect an advertisement of leading to fraud. The 'fear of missing out' tactic is employed instead of the urgency typically seen in conventional phishing, presenting the offers as genuine shopping opportunities.
The Milk Dragon operator panel offers centralized management of visitor information, captured card records, order details, and campaign statistics. It supports multiple phishing pages from a single backend, role-based access, and real-time notifications via browser or Telegram. The use of reusable templates further allows criminals to adapt the attack workflow for specific regions and financial institutions, reflecting a broader trend towards phishing-as-a-service kits that focus on real-time authentication relay.
For individuals, vigilance against extraordinary discounts and unfamiliar social media shops is paramount. Independent verification of retailers and the use of reputation services are advised before submitting payment information. Those who have shared data or codes should immediately contact their banks. Organizations are encouraged to monitor for lookalike domains and suspicious checkout patterns, and to initiate takedown procedures promptly. While specific indicators of compromise are not publicly disclosed, the campaign highlights the evolving sophistication of phishing operations that combine social engineering with advanced technical bypasses.