Group-IB’s latest research on the Milk Dragon phishing kit is a useful reminder that phishing does not have to look like a suspicious email. The campaign, also known as NaiLong, uses social media shopping lures — fake discounts, familiar product categories, and brand-style ecommerce pages — to steer victims into adversary-in-the-middle phishing flows and payment-card theft.

That matters for small businesses and government contractors because these attacks hit the soft middle between consumer fraud, brand abuse, identity compromise, and payment security. Employees may encounter the lure on personal devices. Finance and procurement staff may be more exposed to shopping, vendor, invoice, and payment workflows. A compromised personal or business account can become a foothold for account takeover, card fraud, mailbox abuse, or downstream social engineering.

What Group-IB reported

Group-IB described Milk Dragon as an adversary-in-the-middle phishing kit active since October 2025. Rather than relying only on urgent email lures, operators promote heavily discounted goods through Facebook and TikTok-style marketplace advertisements and posts. The kit then uses fake ecommerce and banking flows to collect sensitive information.

The research highlights several details defenders should pay attention to:

  • Broad victim reach. Group-IB identified victims across 66 countries and 258 phishing pages since October 2025.
  • Social media delivery. The lures are designed to appear as normal shopping opportunities in feeds and marketplace contexts, where users are less likely to be in “security mode.”
  • Brand impersonation. The pages impersonate well-known retail, supermarket, apparel, toy, and consumer-product brands to increase trust.
  • AiTM phishing capability. Group-IB reported 36 banking templates used to conduct adversary-in-the-middle phishing attacks intended to bypass MFA protections.
  • Phishing-as-a-service economics. The kit was reportedly sold through Telegram with developer support, affiliate operations, and panels for monitoring stolen data.

The operational lesson is straightforward: attackers are not just sending bad links. They are running managed fraud infrastructure with advertising funnels, brand-style landing pages, phishing kits, support channels, and operator dashboards.

Why this is not just a consumer scam

It is tempting to file social-commerce phishing under personal fraud. That is too narrow. The same mechanics can affect business environments in several ways.

  • Payment-card exposure. Small businesses often use corporate cards for software, supplies, travel, shipping, and ad-hoc purchases. A fake shopping flow can expose card data that later becomes a finance and reconciliation problem.
  • Password reuse and account takeover. If an employee reuses credentials between personal shopping, email, social media, or work-adjacent services, a consumer-looking phishing page can become a business identity incident.
  • Session theft pressure. AiTM-style kits are built around defeating basic MFA assumptions by proxying login flows and capturing tokens or real-time authentication data.
  • Brand and vendor impersonation. The same playbook used to impersonate retailers can be adapted to impersonate suppliers, benefits portals, contract platforms, document portals, or public-sector services.
  • Helpdesk and finance follow-on risk. Once attackers have personal details, card data, or account access, they can craft more convincing support calls, payment-change requests, refund scams, or mailbox takeover attempts.

For government contractors, this risk intersects with trust. A compromised employee mailbox, supplier portal, procurement card, or social account can be used to stage more believable attacks against customers, partners, or subcontractors. Even when the initial victim was “off network,” the follow-on activity can become a business security problem.

The defender mistake: assuming MFA solves phishing

MFA still matters, but Milk Dragon shows why defenders need to be precise about what kind of MFA they rely on. Push approvals, SMS codes, email codes, and one-time passwords can all be abused in real-time phishing flows. AiTM infrastructure is designed to make the user believe they are completing a normal login or payment verification while the attacker relays the session.

That does not mean MFA failed as a concept. It means organizations should move high-risk accounts toward phishing-resistant options and pair authentication with session, device, and transaction controls.

  • Use passkeys or FIDO2 security keys for administrators, finance staff, executives, and customer-facing accounts where possible.
  • Monitor new devices, new locations, unusual session creation, and token reuse instead of treating a successful MFA event as final proof of legitimacy.
  • Require step-up verification for payment changes, new payees, procurement-card updates, password resets, MFA resets, and sensitive data exports.
  • Separate corporate payment cards and purchasing accounts from personal shopping behavior.

Practical controls for SMBs and government contractors

Milk Dragon is a good case study because the defensive response does not require a huge security program. It requires tightening identity, payment, and brand-abuse controls around the workflows attackers are abusing.

1. Harden finance and procurement workflows

  • Use virtual cards or merchant-locked cards for online purchases where available.
  • Set transaction alerts for procurement cards and require rapid reporting for unexpected charges.
  • Require out-of-band verification before changing vendor bank details, payment destinations, or refund instructions.
  • Limit who can store payment cards in SaaS platforms, ecommerce accounts, shipping portals, and ad accounts.

2. Move high-risk identities to phishing-resistant authentication

  • Prioritize passkeys or hardware-backed FIDO2 for administrators, finance, HR, leadership, and any account with customer data access.
  • Block legacy authentication and reduce reliance on SMS or email-based verification for business accounts.
  • Alert on new MFA methods, new OAuth grants, impossible travel, risky sign-ins, and successful logins from unfamiliar devices.

3. Treat social media and brand abuse as security signals

  • Monitor for fake pages, ads, profiles, domains, and marketplaces impersonating the business or key suppliers.
  • Publish clear customer guidance on official domains, support channels, and payment practices.
  • Give employees a fast way to report suspicious ads, fake stores, or social-media impersonation without embarrassment.

4. Add browser and DNS friction around risky destinations

  • Use DNS filtering and browser isolation for newly registered domains, suspicious ecommerce clones, and uncategorized sites.
  • Warn or block credential submission to domains that are not approved business services.
  • Review logs for users repeatedly visiting fake-shopping, phishing, or carding-related infrastructure.

5. Rehearse the response path

  • Have a short checklist for suspected payment-card exposure: freeze card, review transactions, preserve logs, notify finance, and rotate affected account passwords.
  • Have a separate checklist for suspected business-account phishing: revoke sessions, reset password, review MFA methods, check inbox rules, review OAuth grants, and hunt for suspicious email forwarding or mailbox access.
  • For contractors, document when customer notification, cyber-insurance notice, or contractual reporting may be required.

Bulwark Black assessment

Milk Dragon stands out because it blends consumer psychology with enterprise-relevant attack mechanics. A fake discount ad looks low stakes, but the backend can include AiTM templates, affiliate panels, Telegram support, payment theft, and repeatable infrastructure. That is not a random scam. It is productized fraud.

For SMBs and government contractors, the right takeaway is not “tell users not to click ads.” That advice is too thin. The better answer is to assume some users will encounter convincing social-commerce lures and make sure the business impact is contained. Separate payment workflows. Use phishing-resistant authentication for important accounts. Monitor sessions, MFA changes, OAuth grants, and unusual payment activity. Give employees a no-blame reporting path before a small personal mistake becomes a business incident.

Phishing has moved into the feed. Defense has to move with it.

Original source: Group-IB — Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy.