Cybercriminals are using fake discounts posted on Facebook and TikTok to lure shoppers to phishing sites that steal their payment card details and one-time passwords, Group-IB has warned.
The phishing kit called Milk Dragon (also known as NaiLong) has been active since October 2025, and is linked to 258 phishing pages and victims in 66 countries.
“Milk Dragon differentiates itself from the conventional phishing playbook in a notable way,” GroupIB noted.
Its operators skip fake fines, parcel delivery problems and bank alerts meant to cause fear and urgency. They post malicious links in social media marketplace listings and tempt victims with big exclusive discounts on popular brands and consumer goods.
Milk Dragon’s Phishing flow (Source: Group-IB)
“It hooks victims with a different kind of fear, the fear of missing out (FOMO),” researchers wrote.
The fake shops impersonate 21 brands in cosmetics and fashion, food and beverage, home and baby products and toys, along with regional supermarkets. LEGO, Calvin Klein and Aeon Malaysia are among the names used as bait.
Because the links appear in ordinary marketplace listings, users don’t feel targeted and have fewer reasons to be suspicious, Group-IB explained. The lures are designed to reach people while they scroll on autopilot.
Some of the posts come from what appear to be fake profiles that carry AI-generated content and may have bought followers. “Whether these accounts are managed by the operators themselves or by an underground distribution service is unclear at this moment.”
How the fake checkout works
Once victims engage with the malicious ad or post, they are redirected to a WordPress site disguised as an online retailer selling discounted products. The shop runs on WooCommerce, a legitimate e-commerce plugin, alongside a custom plugin called BytePress that adds a fake credit card option and a fake PayPal option to the checkout.
BytePress also connects the checkout page to the operator’s command-and-control (C2) server through a persistent WebSocket connection. Everything typed into the payment page reaches the operator character by character, even before the form is submitted. Through the same connection, the operator can move the shopper to other pages, accept, reject or block the card, and display custom notifications.
After the card details are submitted, a fake Turnstile loading page appears. Meanwhile, the operator selects a spoofed verification page that mirrors the 2FA challenge issued by the legitimate 3D Secure (3DS) payment site. When the victim enters the one-time password, the operator relays it to approve a fraudulent transaction or take over the account.
The scam ends with a fake order confirmation, which keeps victims from suspecting anything and delays steps such as cancelling the card.
Stolen data that gets reused
Group-IB analyzed the kit’s operator panel and custom plugins, which show how the criminals run their campaigns and scale them up.
“The dashboard gives operators centralized visibility into the performance of all phishing sites tied to the panel. For each site, it shows key metrics including visitor counts, total orders submitted and completed payments, allowing operators to gauge the effectiveness of individual campaigns at a glance.”

Example of real time keystroke capture (Source: Group-IB)
The panel stores payment card details, personal information, device metadata and order details for every victim. Affiliates can return to these records later, which turns each victim into a reusable profile and lets the criminals target people who have already fallen for the scam once.
Operators get an alert in the browser or through a Telegram bot whenever a victim enters data, and each stolen card is tagged by type and issuing bank based on its BIN. A live session view shows what the victim is doing next to the data they have entered.
Affiliates can also build fake verification pages to match the country a campaign targets. The panels examined held templates impersonating 36 financial institutions.
“The kit’s role-based access provides scam syndicates with an easily managed phishing framework without the need to purchase multiple subscriptions. This leads to a lower barrier of entry for less skilled malefactors and increases the volume of victims a single deployment can process, as multiple victims are funneled into a single C2 server,” researchers added.
Group-IB advises users to be wary of ads and third-party links on social media and to treat steep or time-limited discounts as a warning sign. Anyone who has entered card details on such a site should contact their bank or card issuer right away.
Companies should watch for lookalike domains and request takedowns early, and monitor for suspicious card activity and unusual checkout patterns.

