Group-IB has detailed a phishing kit, Milk Dragon, that has been active since October 2025 and is linked to 258 phishing pages with victims in 66 countries. Instead of using fake fines or parcel alerts, the operators post malicious links in social media marketplace listings on Facebook and TikTok, impersonating 21 brands including LEGO, Calvin Klein and Aeon Malaysia. The bait is a steep, time-limited discount that plays on shoppers' fear of missing out.

Victims who click are taken to a WordPress site running WooCommerce with a custom plugin called BytePress. The plugin adds fake credit card and PayPal options and opens a persistent WebSocket connection to the operator's command-and-control server, so every keystroke on the payment page is captured in real time. After card details are submitted, a fake Turnstile loading page appears while the operator selects a spoofed 3D Secure verification page. The one-time password the victim enters is relayed to approve a fraudulent transaction, and a fake order confirmation delays any suspicion.

The kit's operator panel stores card details, personal information and device metadata for each victim, and affiliates can reuse those records to target people who have already fallen for the scam. The panel also includes templates impersonating 36 financial institutions and provides role-based access, lowering the barrier for less skilled criminals. Group-IB advises users to treat steep or time-limited discounts on social media as a warning sign and to contact their bank immediately if they have entered card details on such a site.