Milk Dragon Phishing Kit Turns Social Ads Into Real-Time Card Fraud
A subscription phishing-as-a-service (PhaaS) kit known as Milk Dragon is lowering the bar for payment fraud by handing low-skilled operators a live, hands-on-keyboard view of a victim's checkout session — including the one-time passcode needed to approve a fraudulent transaction.
How the scam works
The lure starts on social platforms, not inboxes: ads for steep discounts on electronics, toys, fashion and everyday goods, sometimes boosted with AI-generated images or bought followers to look credible. Clicking through lands shoppers on a cloned storefront built on WordPress and WooCommerce that mimics a real retailer.
A malicious checkout plugin keeps a persistent connection open between the victim's browser and the fraud operator's control panel. That link lets the operator watch form fields fill in character by character, approve or reject submitted card details, and push the victim toward a fake "verifying payment" screen followed by a counterfeit bank authentication page. When the real one-time passcode arrives, the operator relays it back through the fake page to approve the transaction on the real account — a live adversary-in-the-middle (AiTM) bypass of MFA rather than a static password grab.
Why it matters
The pitch leans on fear of missing a deal rather than the urgency cues people are trained to spot in classic phishing. The back-end panel is built to scale: it centralizes victim and card data across multiple cloned pages, supports role-based operator accounts, and pushes alerts over Telegram — all for a few hundred dollars a month. It's another sign that phishing-as-a-service is shifting from harvesting static passwords to relaying live authentication, which defeats one-time codes sent by SMS or app.
What to do
Treat unusually steep discounts from unfamiliar social media shops as a red flag, and verify a retailer independently before entering payment details rather than trusting the ad itself. Anyone who entered card data or a one-time code on a suspicious checkout page should contact their bank immediately and review recent transactions. Organizations should watch for lookalike storefront domains and unusual checkout flows, and treat phishing-resistant authentication — passkeys or hardware security keys rather than SMS or app-based one-time codes — as the strongest defense, since it removes the value of a relayed passcode entirely.
