World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat

Threat actors are abusing World Cup 2026 ticket scarcity, merchandise demand, and hiring activity to run mobile-first phishing and scam campaigns that steal credentials, payment data, and corporate access. The report highlights three coordinated operations—Ghost Stadium, RetailPhish, and OffsideHire—that use typosquatting, brand impersonation, and AiTM tactics to target fans and enterprise Google Workspace accounts. #FIFA #GhostStadium #RetailPhish #OffsideHire #GoogleWorkspace

Keypoints

  • World Cup 2026 is being exploited as a high-pressure social engineering event due to ticket scarcity, dynamic pricing, and intense fan urgency.
  • The first campaign uses typosquatted and spoofed FIFA ticket sites, including fake domains such as fifa-tickets[.]vip, to steal credentials and payment data.
  • The second campaign, RetailPhish, impersonates brands like Nike and Adidas across multiple languages and uses WhatsApp to spread fake merchandise offers.
  • The third campaign, OffsideHire, targets job seekers with fraudulent FIFA career portals and operates as an Adversary-in-the-Middle platform against corporate Google Workspace accounts.
  • Mobile devices and BYOD usage are a major blind spot because many attacks happen outside corporate VPNs and perimeter controls.
  • Infrastructure shows strong organization, including Cloudflare hiding, shared registrant patterns, rapid domain rotation, and real-time exfiltration to Telegram.
  • Zimperium reports its Mobile Threat Defense can detect and block these threats on-device before credentials or payment details are submitted.

MITRE Techniques

  • [T1566.002] Spearphishing Link – Victims are lured through fraudulent emails, WhatsApp messages, SMS, ads, and search results that direct them to fake FIFA, retail, and job sites (‘The website can be distributed through fraudulent emails, WhatsApp messages, SMS, advertisements, etc.’).
  • [T1583.001] Acquire Infrastructure: Domains – Attackers register lookalike domains to host spoofed ticket, retail, and recruitment pages (‘registering domains that closely resemble official URLs’).
  • [T1036.005] Masquerading: Match Legitimate Resource Name or Location – The kits impersonate official FIFA, Nike, Adidas, and Google login experiences to appear trustworthy (‘replicate the visual language of FIFA’s legitimate careers page’).
  • [T1001.003] Data Obfuscation: Protocol Impersonation – The phishing flow mimics legitimate purchase and login workflows, including fake confirmation pages and login frames (‘pixel-perfect clone of Google’s sign-in page’).
  • [T1185] Browser Session Hijacking – The AiTM platform captures authenticated Google sessions after MFA is completed (‘captures the fully authenticated Google session’).
  • [T1110.003] Brute Force: Password Spraying – Not explicitly described as automated spraying; not applicable.
  • [T1056.001] Keylogging – The page spies on user movement and captures entered credentials and data (‘The website spies on every user’s movement’).
  • [T1218] Signed Binary Proxy Execution – Not mentioned.
  • [T1567.002] Exfiltration to Cloud Storage – Not mentioned.
  • [T1041] Exfiltration Over C2 Channel – Stolen data is sent to the operator backend and Telegram bot (‘Booking data sent to Telegram’).
  • [T1071.001] Application Layer Protocol: Web Protocols – Credentials and booking data are submitted via HTTP POST requests to backend APIs (‘POST /api/login’, ‘POST /api/booking’).
  • [T1078] Valid Accounts – Stolen FIFA and Google Workspace credentials are used for account takeover (‘the stolen credentials are used to lock the user out’).
  • [T1114.001] Email Collection – Not mentioned.
  • [T1557.001] Adversary-in-the-Middle: Application Layer Protocol – The OffsideHire kit relays credentials in real time to Google and intercepts MFA (‘the backend relays them against Google’s real infrastructure’).
  • [T1621] Multi-Factor Authentication Request Generation – The kit dynamically presents interception pages when Google triggers second-factor prompts (‘the kit dynamically presents the corresponding interception page’).
  • [T1204.001] User Execution: Malicious Link – Victims must click the fraudulent links to begin the attack chain (‘The user clicks on a fake FIFA website’).

Indicators of Compromise

  • [Domains ] Fake ticket, retail, and recruitment infrastructure – fifa-tickets[.]vip, fifa-hr[.]com
  • [Domains ] Additional campaign domains and backend – fifa-hiring[.]com, fifajobs[.]com, fifeq2026eqbackeq.onrender[.]com
  • [URLs/Paths ] Phishing URL patterns and API endpoints – /CpnFuYZK/?adidas-equipacion-espana-mundial-2026.html, /api/login
  • [URLs/Paths ] Additional routes used for theft and booking – /api/register, /api/booking
  • [IPs/Servers ] Shared hosting and infrastructure references – Render.com backend, AWS infrastructure
  • [Nameservers ] Cloud and hosting concealment – vera.ns.cloudflare.com, walt.ns.cloudflare.com, ishaan.ns.cloudflare.com, mina.ns.cloudflare.com
  • [Analytics/Tracking IDs ] Victim tracking and retargeting – TikTok Pixel D7S1RAJC77U07JNLHM3G, Facebook Pixel 1147557470844988
  • [Analytics/Tracking IDs ] Telemetry and live chat services – sdk.51.la, collect-v6.51.la, SaleSmartly
  • [File/Technology Names ] Phishing kit and web framework artifacts – React, RSpack 1.3.15, Layui 2.7.6, layer-shim.js


Read more: https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat