Nailong Phishing Toolkit Leverages Social Media for Adversary-in-the-Middle Attacks
A Chinese-language phishing toolkit named 'Milk Dragon' is enabling threat actors to conduct sophisticated adversary-in-the-middle attacks by exploiting social media posts and advertisements.

A new phishing toolkit, identified as Nailong or "Milk Dragon," is empowering cybercriminals with advanced adversary-in-the-middle (AiTM) capabilities, primarily targeting users through social media platforms. Cybersecurity firm Group-IB reports that this toolkit, operational for at least a year, allows less technically adept actors to impersonate popular brands and lure victims with enticing discounts, often featured in e-commerce listings on platforms like Facebook and TikTok.
The "Milk Dragon" toolkit distinguishes itself by eschewing traditional inbox-based phishing or supply-chain attacks, instead focusing on social media channels for distribution. This approach capitalizes on the urgency created by time-sensitive offers and the trust associated with well-known brands. The toolkit's name and branding appear to be a playful reference to a popular Chinese cartoon character, a small yellow dragon, which may contribute to its appeal among its target demographic.
At its core, Nailong offers robust AiTM functionalities, including the use of reverse proxies. These proxies are crucial for intercepting and relaying user credentials and multi-factor authentication (MFA) responses in real-time. When a victim interacts with a malicious link, the reverse proxy forwards their inputs to the legitimate identity provider. This allows attackers to capture not only passwords but also MFA codes and session cookies, effectively bypassing security measures designed to protect user accounts.
The service operates on a subscription model, with monthly plans starting at $300 and annual subscriptions priced at $999, payable in USDT (tether). An optional "build services" add-on, costing 99 USDT per month, provides comprehensive support for users lacking technical expertise. This support includes server configuration, domain registration, template installation, and integration assistance, further lowering the barrier to entry for aspiring phishers.
Group-IB's analysis indicates that Nailong users have primarily targeted victims in Southeast Asia, with significant numbers reported in Malaysia, Thailand, and Singapore. However, victims have also been identified in Canada, France, the United States, and the United Kingdom. The toolkit provides templates designed to spoof verification pages for 36 different financial services firms, highlighting its focus on financial data theft.
Attackers using Nailong typically direct victims to a WordPress site that mimics legitimate e-commerce platforms. These sites often use the WooCommerce plugin for realistic checkout pages, augmented by a custom plugin called BytePress. BytePress facilitates command-and-control (C2) communication and guides victims through a simulated purchase process. After submitting details, victims encounter a fake 3D Secure (3DS) verification page, where the toolkit intercepts the one-time code to complete fraudulent transactions or gain account access.
Defending against such sophisticated campaigns is challenging due to the attackers' use of proxy networks to obscure the true origin of their attacks. This obfuscation makes it difficult for network defenses to identify the malicious infrastructure. The rise of "cloaking services," such as Cloaked.gg, further complicates detection efforts by actively concealing phishing infrastructure from automated analysis systems.
The "Milk Dragon" toolkit exemplifies a growing trend of accessible, feature-rich phishing-as-a-service offerings. By combining social engineering tactics with advanced AiTM capabilities and simplifying the technical requirements for deployment, these toolkits significantly lower the bar for cybercrime, posing an escalating threat to individuals and organizations globally.