GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com PingIdentity SSO Credential-Theft Sites

GHOST STADIUM (TL-2026-0704), also tracked as Ghost Stadium Operation, is a high-severity phishing campaign, first published 2026-06-07. It is attributed to Ghost Stadium (China) with medium confidence, affects FIFA fifa.com / FIFA account holders (PingIdentity SSO), maps to 20 MITRE ATT&CK techniques (T1056.003, T1098, T1110.004), and is covered by 9 detection rules and 48 indicators of compromise.

Key facts for TL-2026-0704

Threat ID
TL-2026-0704
Also known as
Ghost Stadium Operation, FIFA World Cup 2026 Phishing Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-06-07
Last reviewed
2026-06-07
Attribution
Ghost Stadium
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
sports, entertainment, retail, consumer, ticketing, general-public
Target regions
North America, Europe, Latin America, Asia, Middle East, Global
Detection rules
9
Indicators of compromise
48

Malware and tooling in GHOST STADIUM

Malware and tooling: Lumma, Vidar

Group-IB uncovered GHOST STADIUM, a Chinese-speaking, financially motivated phishing operation that registered 4,300+ fraudulent FIFA domains since August 2025 and runs 300+ live sites cloning fifa.com — including a pixel-perfect PingIdentity SSO flow. The kit harvests credentials and PII, silently redirects victims to the real fifa.com/auth to mask the theft, and abuses the PingIdentity 'p1:reset:userPassword' scope to reset victim passwords and lock them out. ~3,800 additional domains sit parked for activation around the June–July 2026 tournament; the FBI/IC3 corroborated the campaign in PSA260527.

How GHOST STADIUM works

GHOST STADIUM is a large-scale, profit-driven phishing and fraud operation targeting fans of the 2026 FIFA World Cup. Group-IB attributes the campaign to four distinct threat-actor clusters operating six fraud schemes, with GHOST STADIUM (TA-1) as the lead actor controlling 300+ live phishing domains. Group-IB tracked 4,300+ fraudulent FIFA-themed domains registered since August 2025 — 300+ actively serving phishing content, 140+ flagged suspicious, and ~3,800 parked and pre-positioned for activation as the tournament approaches.

The GHOST STADIUM phishing kit is a React-based single-page application that clones the official fifa.com site to near pixel-perfect fidelity, using the Chinese open-source Layui 2.7.6 UI framework. It replicates FIFA's legitimate PingIdentity SSO authentication flow, reusing the genuine client_id 35072598-fc20-4142-a469-1b940db47e6f. Critically, the kit's OAuth scope parameters include 'p1:reset:userPassword', which lets the operator trigger a password reset on the victim's real FIFA account immediately after capturing credentials — locking the legitimate owner out while the attacker retains control. After harvesting login credentials, email, phone, and address data, the kit performs a silent redirect to https://www.fifa.com/auth/ so the victim believes the login succeeded and never notices the compromise.

The kit supports 14 locales (11 languages plus Simplified, Traditional, and Hong Kong Chinese variants), loads FIFA branding and product imagery directly from FIFA's official CDN for visual legitimacy, and embeds a Google Translate widget and authentic-looking social footer. Attribution to a Chinese-speaking actor rests on the Layui framework choice, Chinese-language source-code comments, and the granular mainland/Taiwan/Hong Kong locale distinctions.

Infrastructure is heavily clustered: 300+ domains share SSL certificates, identical Meta (Facebook) Pixel IDs, a shared Tawk.to live-chat Property ID (6976ccbaba77e8198a866266), and byte-for-byte identical 415 KB HTML across 79 premium/hospitality domains. 57% of the cluster was registered through GNAME.COM PTE. LTD. Victim acquisition runs primarily through Facebook Ads and organic Google search ranking of typosquat/themed domains, with Telegram and WhatsApp for distribution and victim support.

Monetization is diversified across five payment channels: direct card capture (Order ID format FWC2026XXXXXXXXX), a third-party gateway at pay.zfxupi.net (routing Cash App/Chime), peer-to-peer transfers (Chime cashtag $Paramjit-Bains, Nequi account 3202059757), region-specific rails (FIXYD Mexico via mm-fifa.top), and a crypto on-ramp via Alchemy Pay converting USD to USDT on Binance Smart Chain (ChainUGO gateway). Group-IB estimates premium/hospitality ticket fraud alone (79 domains, ~47,400 victims) at $71M–$474M, with total campaign losses potentially reaching billions.

The broader ecosystem includes TA-2 (bulk domain squatter, ~143 domains for fake streaming, counterfeit merchandise, and betting), TA-3 (Vidar/Lumma infostealer operators with ~130,000 logs referencing FIFA), and TA-4 (dark-web phishing-as-a-service kit sellers active since mid-2025). 2,513 FIFA credential pairs are already circulating in dark-web markets at $5–$50 each. The FBI's IC3 PSA260527 independently warned of FIFA website spoofing via typosquatting (e.g., fiffa.com, wvvw-fifa.com homograph), alternative TLDs, and fake subdomains such as jobs-fifa.com and fifa-hiring.com.

MITRE ATT&CK techniques used in TL-2026-0704

Credential Access

T1056.003 Web Portal Capture; T1110.004 Credential Stuffing; T1539 Steal Web Session Cookie; T1606 Forge Web Credentials

Persistence

T1098 Account Manipulation

Impact

T1531 Account Access Removal; T1657 Financial Theft

Initial Access

T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice

Resource Development

T1583 Acquire Infrastructure; T1583.001 Domains; T1583.006 Web Services; T1583.008 Malvertising; T1587.001 Malware; T1588.001 Malware; T1608.005 Link Target

Reconnaissance

T1589.001 Credentials; T1589.002 Email Addresses; T1598.003 Spearphishing Link

Defense Evasion

T1684.001 Impersonation

Affected products and versions in GHOST STADIUM

  • FIFA — fifa.com / FIFA account holders (PingIdentity SSO)
    Vulnerable versions: FIFA account holders and World Cup 2026 ticket/merchandise buyers
  • Ping Identity — PingOne SSO (impersonated, not a product vulnerability)
    Vulnerable versions: Legitimate FIFA PingIdentity SSO flow cloned by phishing kit

Remediation for GHOST STADIUM

Immediate actions

  • Type fifa.com directly into the address bar or use a saved bookmark; never reach FIFA login via search engines or sponsored results
  • Block the listed phishing domains, redirector domains, and hosting IPs at web proxies, DNS resolvers, and email gateways
  • Alert FIFA account holders to reset passwords from the legitimate site and enable MFA; watch for unsolicited password-reset notifications indicating compromise
  • Block payment-channel identifiers (pay.zfxupi.net, mm-fifa.top, Chime cashtag $Paramjit-Bains, Nequi 3202059757) where transaction monitoring is possible

Workarounds

  • Verify SSO login URLs resolve to genuine FIFA/PingIdentity domains before entering credentials
  • Avoid suspicious sites with unprofessional design, non-.com TLDs, or homograph characters

Longer-term hardening

  • Deploy brand-protection and anti-phishing domain monitoring for FIFA/World Cup typosquats and newly registered look-alike domains
  • Submit takedown requests to registrar GNAME.COM and abused platforms (Facebook Ads, Tawk.to, billplz, Alchemy Pay)
  • Educate fans on official ticketing/merchandise channels and PingIdentity SSO domain verification
  • Integrate credential-leak monitoring for fifa.com/fifa.org pairs appearing in infostealer logs and dark-web markets

Weaknesses (CWE) in GHOST STADIUM

CWE-290, CWE-451, CWE-1021

Timeline of GHOST STADIUM

  • Earliest fraudulent FIFA-themed domain registrations begin; start of the 4,300+ domain registration wave tracked by Group-IB.
  • TA-4 dark-web phishing-as-a-service vendors active since mid-2025, selling pre-built FIFA phishing kits, bots, and templates.
  • Group-IB begins technical analysis of the GHOST STADIUM cluster (March–May 2026 research window).
  • Redirector domains (football-ticket[.]top/shop, football-game[.]shop, football-tickets[.]top) registered on shared origin IP 43.98.183[.]110.
  • Group-IB publishes the GHOST STADIUM report; FBI/IC3 issues PSA260527 warning of FIFA website spoofing on the same day.
  • Infosecurity Magazine and other outlets report on the thousands of fake FIFA domains targeting World Cup fans.
  • FIFA World Cup 2026 begins (June 11–July 19, 2026); ~3,800 parked domains expected to activate for peak fraud during the tournament window.

Sources cited for GHOST STADIUM

Threats related to GHOST STADIUM

Detection coverage for TL-2026-0704

As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0704 across Splunk SPL, Microsoft KQL and Sigma, covering 48 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats