Scams & Phishing These social media posts promise big online discounts on Lego, Calvin Klein and more — but really they're just phishing scams

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
An elaborate scheme is making the rounds on Facebook and TikTok
  • Milk Dragon uses fake ecommerce sites and social media deals to steal payment data
  • Malware captures credentials and MFA codes in real time, even before form submission
  • Campaign targeted victims in 66 countries, abusing trusted brands and banks
If you come across a post on social media promoting huge discounts on major brands such as Lego or Calvin Klein, be extra careful, as security researchers Group-IB have warned these could be fake, and part of an elaborate scheme to steal your money.

In their report, the researchers said they uncovered a major scam campaign run by a group they are calling Milk Dragon.

For at least a year now, this threat actor has been using a phishing kit of the same name to create spoofed versions of popular ecommerce websites, sometimes even using AI to create entirely fake listings.

Phishing with a spin
Fake ecommerce sites with offers simply too good to pass up on are not a new tactic.

Recent FTC Consumer Sentinel data shows 376,830 reports in the "online shopping and negative reviews" category in 2023, with nearly $400 million in reported losses. The median reported loss was $126, with more than half of reports involving financial losses.
What makes this campaign unique is that it abuses trusted channels - social media groups and pages - to deliver the lure. Usually, these lures would be sent out via phishing emails, but since email providers have caught up with most of the tactics and have become rather good at filtering spam, threat actors turned to the next best thing - social media.

In this case, the listings were shared on Facebook and TikTok mostly, Group-IB said, primarily in groups where users hunt for similar bargains. That way, they might not even realize they are actually being targeted by an advanced infostealer.
As Group-IB explained, the websites come with a piece of malware called BytePress which captures all of the information submitted and sends it to the attackers’ command-and-control panel.

What makes BytePress particularly dangerous is the fact that victims don’t even have to submit the information - simply typing it into the form is enough, since the malware can stream what the victim types character by character, in real-time.

When the victim finally submits the data, it gets relayed through attacker infrastructure to the legitimate website, which often returns requests for one-time passwords and similar multi-factor authentication. The request is sent back to the victim and once again picked up, defeating any multi-factor authentication they might have set up.
Buying time
In the end, the victim will get a fake order confirmation, and Milk Dragon will display what appears to be a successful purchase. That way, the victim will believe everything is in order and won’t rush to contact their bank and freeze their credit card or reset their credentials. In the meantime, crooks can use those details in whatever malicious way they please.

Milk Dragon doesn’t seem to be targeting any country, or people, specifically. It cast a relatively wide net, with victims being found in 66 countries around the world. However, according to Group-IB’s report, the majority of the victims were found in three countries: Malaysia (1,300+), Singapore (1,200+), and Thailand (1,100+).

The group also doesn’t seem to be particularly fond of any specific brand. A total of 21 popular brands were spoofed, across cosmetics & fashion, food & beverages, home & baby products, as well as toy industries. Regional supermarkets are also frequent impersonation targets, it seems, as well as 36 financial institutions and banks.

The Milk Dragon phishing kit is being sold on Telegram channels as a service, with various hacking groups paying either monthly, or yearly fees. The tool is being sold from 300 USDT (cryptocurrency) a month, with various subscription plans and add-ons.
 
Hi Brownie, this is a nasty campaign because it combines a convincing shopfront with a live, operator-controlled checkout. Group-IB identified 258 phishing pages since October 2025, impersonating 21 retail brands and 36 financial institutions across 66 countries. Their technical report supports the central warning.

Two useful technical distinctions:

  • BytePress is a malicious WordPress/WooCommerce plugin on the scam site, not necessarily an infostealer installed on the victim’s computer. Its browser-side code uses a persistent WebSocket connection to stream checkout input to the criminals character by character. Merely visiting one of these sites therefore does not, by itself, establish that the device was infected.
  • “Before submission” applies to information typed into the checkout fields. The MFA or 3-D Secure step comes later: the operator relays a genuine bank challenge to the victim and captures the resulting code or approval in real time. That is adversary-in-the-middle phishing, not a cryptographic defeat of MFA. OTP-based verification remains phishable.

That affects the response:

  • Only viewed the page: close and report it; the described mechanism does not indicate that card details were stolen if none were entered.
  • Typed card details but abandoned the form: assume whatever was typed may already have been captured. Lock the card and contact the issuer.
  • Entered a bank/PayPal password: use the genuine app or a manually entered official address to change it, revoke active sessions and review account activity.
  • Entered an OTP or approved a banking prompt: contact the bank’s fraud department immediately and check pending transactions; do not wait for the fake “order” to fail.
  • Downloaded or executed anything: that becomes a possible endpoint compromise and is appropriate for MalwareTips’ Malware Removal Assistance team.

The padlock is no defence here—it can encrypt your connection perfectly while delivering your details securely to the crook. Going to the retailer through its official app, bookmark or independently typed address remains the safer habit.

One small numerical correction: the FTC’s 2023 Consumer Sentinel Data Book records 369,469 reports in that category overall; its fraud-loss table lists 368,379 reports, 53% reporting a loss, $392 million total losses and a $125 median. The quoted 376,830/$126 figures do not match the published data book, although that does not alter the warning about Milk Dragon.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top