Milk Dragon Targets WooCommerce
The phishing kit known as Milk Dragon, or NaiLong, operates through counterfeit online storefronts to illicitly acquire payment credentials and authentication codes.
Researchers from Group-IB have identified an alarming 258 phishing websites linked to this operation since October 2025, affecting victims in 66 different countries.
The deceptive strategy merges authentic WooCommerce checkout interfaces with a nefarious WordPress plugin dubbed BytePress.
In contrast to typical phishing schemes that hinge on urgent banking warnings or delivery issues, Milk Dragon lures consumers with enticing discounts.
The perpetrators disseminate fraudulent offers via platforms such as Facebook and TikTok, cleverly employing familiar brands and everyday items to enhance the credibility of their advertisements.
Researchers have documented the impersonation of 21 distinct brands spanning sectors like fashion, cosmetics, food, household supplies, and toys.
Among the affected brands are notable names such as LEGO, Calvin Klein, and Aeon Malaysia. Additionally, the kit encompasses templates from 36 financial institutions for the purpose of capturing authentication details.
Milk Dragon Targets WooCommerce
Consumers who engage with these misleading ads are directed to WordPress sites masquerading as legitimate retailers, utilizing WooCommerce to forge recognizable shopping and checkout experiences.
The malicious conduct is facilitated by BytePress, a plugin installed alongside the authentic commercial platform.
BytePress interjects counterfeit credit card and PayPal payment options into the checkout dialogue. Its configuration page features an “API Base URL” that links the fraudulent store to the operator’s command-and-control server.
The plugin creates an enduring WebSocket connection via Socket.IO that links the victim’s browser to the criminal’s backend.
This connection transmits payment input data character by character, enabling operators to harvest information prior to the shopper completing the transaction.
Furthermore, the operators possess the capability to manipulate the pages displayed to victims, present customized messages, and either approve or decline submitted payment details.
This interactive control empowers attackers to tailor their deception while the shopper remains engaged with the website.
Upon acquiring credit card information, the site showcases a counterfeit loading screen. Victims are subsequently redirected to imitation verification pages that mimic legitimate 3D Secure payment services.
When a victim inputs a one-time password, the operator can utilize it to authorize a fraudulent transaction.
This adversarial workflow circumvents reliance solely on stolen card numbers by targeting the very authentication process itself.
A fabricated order confirmation page finalizes the ruse, fostering a false sense of accomplishment among shoppers and potentially postponing reports of fraud or card cancellation.
Milk Dragon has been commercially available in Telegram communities since at least October 2025, with subscription costs commencing at 300 USDT per month, alongside additional plans and optional functionalities. Developers offer updates and customer support to facilitate the operation of affiliates.
The central management panel accommodates multiple phishing websites, implements role-based operator accounts, issues browser alerts, and sends notifications via Telegram.
It meticulously logs visitor interactions, order statistics, payment information, personal data, and device metadata.

Affiliates can initiate a containerized management panel through a streamlined installation interface that prompts for server connection details. The requisite database and API services are automatically configured, simplifying the overall setup process.
Source link: Cyberpress.org.




