AI News Feed
Market watch
Cybersecurity

Milk Dragon Phishing Scam Uses Fake Lego and Calvin Klein Deals on Social Media, Group-IB Says

Milk Dragon runs social media phishing scams using fake shops and malware to steal payment data and MFA codes.

In a report, Group-IB said the campaign has been active for at least a year and uses a phishing kit of the same name to build spoofed versions of popular ecommerce websites. Some listings are generated with AI, the researchers said. The lures are distributed mainly through Facebook and TikTok, often in groups and pages where users look for bargains. By using trusted social media channels rather than email, the operators try to reach victims who may not realize they are being targeted by an advanced infostealer, Group-IB said.

The fake shops deploy malware called BytePress, which Group-IB said captures information entered into forms and sends it to the attackers' command-and-control panel. The malware can stream what a victim types character by character in real time, meaning the data can be stolen before the victim submits the form. When the victim does submit the information, it is relayed through attacker infrastructure to the legitimate website. That site may then request a one-time password or other multi-factor authentication. The request is sent back to the victim and intercepted again, allowing the attackers to defeat MFA protections, according to the report.

After the transaction, the victim receives a fake order confirmation and sees what appears to be a successful purchase. Group-IB said this is intended to prevent victims from quickly contacting their bank to freeze a credit card or reset credentials while the stolen details are used for other fraudulent activity.

The campaign has not been limited to one country or brand. Group-IB said victims were found in 66 countries, with the largest numbers in Malaysia, where there were more than 1,300 victims, followed by Singapore with more than 1,200 and Thailand with more than 1,100. The group spoofed 21 popular brands across cosmetics and fashion, food and beverages, home and baby products, and toys. Regional supermarkets and 36 financial institutions and banks were also frequently impersonated, according to the report.

Group-IB said the Milk Dragon phishing kit is sold on Telegram channels as a service, with hacking groups paying monthly or yearly fees. The tool starts at 300 USDT a month, with various subscription plans and add-ons.

The warning comes as online shopping fraud remains a significant problem. Recent Federal Trade Commission Consumer Sentinel data cited by TechRadar showed 376,830 reports in the online shopping and negative reviews category in 2023, with nearly $400 million in reported losses. The median reported loss was $126, and more than half of the reports involved financial losses.

Group-IB said fake ecommerce sites with offers that seem too good to pass up are not a new tactic. What distinguishes this campaign is its use of social media groups and pages to deliver the lure, a shift that follows improvements in email filtering that have made traditional phishing emails less effective. The researchers advised users to be cautious about social media posts promoting deep discounts from major brands.

Editor's Summary

Group-IB has identified a phishing campaign called Milk Dragon that uses fake social media deals on brands such as Lego and Calvin Klein to direct victims to spoofed ecommerce sites. The operation uses BytePress malware to capture payment data and MFA codes in real time and has affected victims in 66 countries, with the highest counts in Malaysia, Singapore and Thailand. The phishing kit is sold on Telegram, and Group-IB says users should be cautious about deep-discount offers promoted on social media.