The National Cybersecurity Agency (NAK), under the Ministry of Digital Development and Transport of Azerbaijan, has detected a phishing campaign conducted under the brand name "MilliÖn". This was reported by the agency.
As a result of monitoring open sources, a fraudulent campaign was identified that uses the name and visual style of the payment system "MilliÖn". The scammers promise users a package of mobile internet and call minutes for 1 manat.
The pages found on the domains million-az.shop and millionaz.site are presented as official payment forms. However, the amount of data requested significantly exceeds what is necessary for a payment of 1 manat and includes the cardholder's name, card number, expiration date, CVV code, phone number, and IP address.
Analysis of the source code shows that the entered data is not transmitted to the payment system, but may be sent to a third party through the site's management script. This indicates that the main purpose of the pages is not to accept payments, but to collect bank card details.
The campaign is spread through social networks. On TikTok and Instagram, accounts imitating the legitimate brand have been identified, containing links to various phishing domains. The view count of individual videos exceeds 231,000 and 496,000.
The use of a similar template called "AzərPay" indicates that the campaign is not limited to one domain or one account. This approach increases the risk of quick replacement of blocked resources with new ones.
The main threat lies in the interception of users' bank card data and its subsequent use in illegal operations. Blocking domains, closing social media accounts, informing banks, and openly warning citizens should be carried out in parallel.

