Milk Dragon Phishing Kit Relays Bank OTPs in Real Time to Bypass MFA Across 66 Countries
A phishing kit called Milk Dragon is defeating the one-time codes banks rely on to stop card fraud, and it is doing it live. Group-IB researchers found 258
A phishing kit called Milk Dragon is defeating the one-time codes banks rely on to stop card fraud, and it is doing it live. Group-IB researchers found 258 phishing pages across 66 countries built on the kit, along with 36 verification templates that mimic real financial institutions, Cyber Security News reports.
The scam starts somewhere ordinary: a Facebook or TikTok ad for a deep discount. Victims click through to a convincing fake store running on WordPress and WooCommerce, dressed up as one of 21 impersonated brands, including LEGO, Calvin Klein and Aeon Malaysia.
The checkout is where it gets nasty. A malicious plugin called BytePress adds fake card and PayPal payment options and holds open a Socket.IO WebSocket to the operator. Every keystroke streams across character by character, so the criminal sees the card number before the victim even presses submit.
Then comes the trick that beats MFA. The victim sees a fake loading or turnstile screen while the operator picks a matching 3-D Secure template for the victim's bank. When the real one-time code arrives by text, the victim types it into the fake page, and the operator relays it in real time to authorize the fraudulent charge before it expires, according to GBHackers.
Milk Dragon, also tracked as NaiLong, has been active since October 2025 and is sold as a service on Telegram. Around 300 USDT a month buys an operator panel, updates and customer support, which puts real-time MFA bypass within reach of almost anyone.
It is a reminder that phishing keeps getting more industrial, whether it targets shoppers or policy experts courted by China's TA419 with AI lures, and that attackers will route around any defense that depends on a human typing a code. Even security products are not immune, as the recently exploited FortiMail zero-day showed. For Milk Dragon's victims, the code that was supposed to protect them is exactly what got stolen.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free