Offside and Online: GHOST STADIUM Phishing Targeting World Cup Fans

Offside and Online: GHOST STADIUM Phishing Targeting World Cup Fans

Researchers exposed GHOST STADIUM, a FIFA-themed phishing kit linked to thousands of fraudulent World Cup-related domains, many of which impersonate ticketing, streaming, or gambling services. The infrastructure shows signs of shared kit deployment, Chinese-language developer artifacts, and heavy Cloudflare fronting, with at least 3,079 domains still active at the time of analysis. #GHOSTSTADIUM #FIFA #Validin #GroupIB

Keypoints

  • Group-IB’s report on GHOST STADIUM described a phishing kit aimed at World Cup fans and ticket buyers.
  • The analysis and follow-on hunting identified 6,113 suspected domains, with 3,079 still active and resolving at the time of review.
  • Most active domains were not obvious ticket scams; many posed as streaming or gambling sites, including Chinese- and Indian-language pages.
  • Multiple pivots revealed shared infrastructure, including identical HTML responses, repeated redirect paths, and kit-specific HTML strings.
  • Chinese-language Google Translate initialization comments in the JavaScript suggest developer artifacts consistent with the attribution assessment.
  • Most active domains were fronted by Cloudflare, making origin infrastructure harder to inspect directly.
  • Defenders were advised to watch for the anomalous HTML strings, repeated World Cup path variants, and FIFA-themed lookalike domains.

MITRE Techniques

  • [T1583.001] Acquire Infrastructure: Domains – The operators registered large numbers of domains to support the phishing campaign, including lookalike and branded domains. [‘roughly 4,300 fraudulent domains’ and ‘6,113 suspected domains’]
  • [T1583.003] Acquire Infrastructure: Virtual Private Server – The broader campaign infrastructure was deployed across hosted web infrastructure, though origin visibility was often obscured by fronting. [‘All active domains observed in this set are using Cloudflare to mask origin infrastructure’]
  • [T1584.001] Compromise Infrastructure: Domains – The domains were used to host fraudulent FIFA-themed pages and mimic legitimate ticket vendors and related services. [‘domains across different themes’ and ‘pose as English-language ticket vendors’]
  • [T1036] Masquerading – The pages and domains impersonated FIFA, ticketing, hospitality, streaming, and gambling services to appear legitimate. [‘FIFA World Cup 2026™ Tickets’ and ‘posing as streaming or gambling sites’]
  • [T1566.002] Phishing: Spearphishing Link – Victims were likely directed to fraudulent websites via deceptive links to ticketing and World Cup-themed pages. [‘phishing kit targeting World Cup fans and ticket buyers’]
  • [T1102] Web Service – The campaign leveraged Cloudflare fronting and web-hosted content to obscure infrastructure and deliver phishing pages. [‘All active domains observed in this set are using Cloudflare to mask origin infrastructure’]
  • [T1071.001] Application Layer Protocol: Web Protocols – The kit served content over HTTP(S) and used web paths and response-body features for distribution. [‘Searching Validin response history for this path returned approximately 600 domains’]
  • [T1027] Obfuscated Files or Information – The operators used malformed strings and developer comments that acted as fingerprints while concealing intent behind plausible-looking content. [‘anomalous 2026TOfficial token’ and ‘Google Translate initialization function’]

Indicators of Compromise

  • [Domains] seed and lookalike phishing domains – fifa-ticket-26[.]com, fifa[.]click, worldcupticket[.]vip, and other N items
  • [URLs/Paths] repeated redirect/content paths used by the kit – /en/tournaments/mens/worldcup/canadamexicousa2026, /en/tournaments/mens/worldcup/canadamexicousa2026.html
  • [File/Content Strings] HTML fingerprints used to identify kit pages – “FIFA World Cup 2026TOfficial Hospitality”, “Experience the best of the World Cup with premium tickets food &drinklounge entry and more!”
  • [Favicon Hash] favicon associated with related domains – 1ea068c804e8ba88b84f6e9598e3172d
  • [YARA Rule Strings] Chinese-language developer comments in JavaScript – “Google翻译初始化函数”, “网站默认语言”
  • [Domain Patterns] lookalike regex results and campaign naming patterns – fifa-.*, .*world.*cup.*, .*ticket.*, and f[i1l]fa-based substitutions


Read more: https://www.validin.com/blog/ghost_stadium/