Malaysia, Singapore, and Thailand are absorbing the heaviest concentrations of an active phishing campaign spanning 66 countries, where threat actors deploy fake ecommerce listings for major brands like Lego and Calvin Klein to harvest credit card details and bypass multi-factor authentication in real time, Group-IB reported.
Social Media Feeds Target Lowered Guards
Unlike traditional phishing schemes that rely on bulk spam emails or fabricated parcel delivery alerts, the Milk Dragon campaign specifically targets users where their guard is typically lowered: organic social media feeds and online bargain-hunting groups. According to Group-IB, threat actors primarily use Facebook and TikTok to promote steep, too-good-to-pass-up discounts on household brands. When unsuspecting shoppers click these advertisements, they land on sophisticated spoofed ecommerce storefronts built using the Milk Dragon phishing kit, which has been actively sold on Telegram since October 2025 for a starting price of 300 USDT per month.
The operation casts a remarkably wide net. Security telemetry indicates that victims span 66 countries, with the heaviest concentrations observed in Malaysia, Singapore, and Thailand. Rather than focusing on a single industry, the campaign has impersonated 21 popular brands across cosmetics, fashion, food and beverages, home and baby products, and regional supermarket chains, alongside 36 financial institutions.

BytePress Powers Real-Time Interception
The technical core of the operation relies on a piece of malware dubbed BytePress, integrated directly into the fraudulent storefronts. BytePress does not wait for a user to hit a submit button to harvest their credentials. Instead, the malware streams input data character by character in real time as the victim types into payment and login forms on the spoofed site.
This live data harvesting feeds directly into the attackers’ command-and-control panels, enabling adversary-in-the-middle attacks. When a victim attempts a transaction, the stolen credentials are relayed instantly to the legitimate website. If the authentic bank or service triggers a one-time password or multi-factor authentication challenge, the request is bounced back through the attacker’s infrastructure to the victim. Once the user inputs their code, the attackers intercept it to finalize unauthorized access before the victim realizes anything is amiss.
Fake Confirmations Mask Active Fraud
To prevent immediate panic and buy time for fraudulent transactions, the phishing kit concludes the user journey with a fake order confirmation page. The interface mimics a successful purchase, reassuring the victim that the transaction went through smoothly. Because the user believes their order is legitimate, they are far less likely to immediately contact their bank, freeze their credit cards, or reset compromised credentials.
Security researchers identified 258 distinct phishing pages associated with the Milk Dragon infrastructure since the campaign’s emergence. The kit’s availability as Phishing-as-a-Service on Telegram channels ensures that various malicious operators can easily deploy customized templates targeting specific regional banks and retailers with ongoing developer support.
- Cornell University Sexual Assault Case: The “I Am Jane Doe” Movement Explained
- Security executives say annual training fails to drive behavioral change
- Florian Wirtz: Klopp and German media praise Liverpool man after Greece game (world-today-news.com)
- Sony Pictures releases Aaron Sorkin’s The Social Reckoning, THR reports (newsdirectory3.com)