Phishing Campaign Exploits FOMO With Counterfeit Brand Deals on Social Platforms

Cybercriminals operating the Milk Dragon phishing kit have targeted 258 phishing pages across 66 countries by leveraging fake brand discount offers on Facebook and TikTok to lure victims to malicious checkout pages. The scheme uses WooCommerce with a custom plugin called BytePress that harvests payment card details and one-time passwords character-by-character through a command-and-control connection. The campaign impersonates major brands including LEGO and Calvin Klein, relying on fear of missing exclusive deals rather than traditional scare tactics.
The Milk Dragon operation demonstrates a shift in phishing strategy away from panic-based tactics. Rather than fabricating urgent warnings or threatening consequences, operators exploit natural consumer behavior by embedding fraudulent offers within familiar social platforms where shoppers browse casually. The infrastructure behind the campaign uses legitimate WordPress tools paired with a custom plugin that intercepts sensitive information in real time, allowing operators to monitor keystrokes before submission and dynamically respond to each victim's actions.
The captured victim data becomes a persistent asset for the criminal network. Payment information, personal details, and behavioral patterns are retained in a centralized dashboard, enabling operators to re-target individuals or sell profiles to affiliated fraudsters. This archival approach transforms each successful compromise into a long-term revenue stream rather than a one-time theft.
This campaign may significantly impact online shoppers who trust social media marketplaces as discovery channels. Victims could face financial losses through fraudulent transactions, identity theft risks from harvested personal data, and account takeovers via intercepted authentication codes. Small retailers using legitimate platforms may also suffer reputational damage if consumers become skeptical of discounted offers. The operation's scale across 66 countries suggests attackers are systematically testing social platforms' current defenses against marketplace-based fraud.