Large-Scale Scam and Impersonation Campaign Targeting Commercial Airline Industry (11,600+ Malicious Domains, 35+ Brands)

Large-Scale Scam and Impersonation Campaign Targeting (TL-2026-1524), also tracked as Ghost Stadium (related FIFA World Cup 2026 phishing cluster), is a medium-severity phishing campaign, first published 2026-02-24. It has no confirmed attribution, affects LATAM Airlines Booking/loyalty portal brand, maps to 25 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-1524

Threat ID
TL-2026-1524
Also known as
Ghost Stadium (related FIFA World Cup 2026 phishing cluster)
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-02-24
Last reviewed
2026-02-24
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
aviation, transport, travel, hospitality, finance
Target regions
Global, North America, 005 - South America, Europe, Middle East, Asia-Pacific
Detection rules
9
Indicators of compromise
19

Malware and tooling in Large-Scale Scam and Impersonation Campaign Targeting

Malware and tooling: BTMOB, Massiv, Perseus

BforeAI PreCrime Labs identified 1,799 suspicious domains registered between September-December 2025 (part of a broader 11,600+ domain dataset) impersonating 35+ global airline brands, deploying phishing booking portals, fake mobile apps, cryptocurrency/meme-coin fraud, fake job/vendor portals, fake support portals, gambling sites, and FIFA World Cup 2026 ticket lures to harvest credentials, PII, and payment data from travelers and airline employees.

How Large-Scale Scam and Impersonation Campaign Targeting works

Between September and December 2025, BforeAI's PreCrime Labs tracked 1,799 suspicious domains directly impersonating 35+ global commercial airline brands -- including LATAM, Avianca, British Airways, EasyJet, United Airlines, Qatar Airways, Ryanair, Lufthansa, AirAsia, IndiGo, Qantas, Batik Air, and Etihad -- as part of a much larger dataset of 11,600+ domains abusing the airline industry across all fraud categories. Roughly 10,000 of those domains used generic travel keywords ("airline", "flight", "charter", "airfare", "private jet") rather than a specific brand name, producing broad, non-targeted phishing infrastructure that casts a wider net than brand-specific attacks and exceeds prior-year totals observed across the entire online travel agency (OTA) industry.

The campaign spans multiple abuse categories operating concurrently: (1) booking-portal and check-in-page phishing that mimics legitimate airline UX to harvest payment card data and PII; (2) loyalty-program and rewards-account phishing using keywords such as "points", "miles", "rewards", and "cards"; (3) cryptocurrency and meme-coin fraud, including fake branded tokens (AirIndiaCoin, IndigoCoin) and fraudulent crypto payment options for flight bookings, several of which were opportunistically spun up around viral industry news (e.g., the Ryanair-vs-SpaceX-CEO public dispute); (4) fake job/recruitment and vendor-onboarding portals using "hiring", "career", "employee", and "partner" language, some password-protected to appear legitimate, soliciting resumes and identity documents from prospective airline employees and contractors; (5) fake customer-support portals stood up during real service disruptions (e.g., IndiGo's flight-cancellation crisis) requesting booking references and payment details under time pressure; (6) gambling/betting sites abusing airline branding and VIP/bonus language (e.g., "WinAirlines Casino" targeting Italian-speaking users, AirAsia betting-themed domains); (7) fake mobile applications distributing malware under airline branding, including Qatar Airways-themed apps used for credential harvesting; (8) AI/LLM-buzzword exploitation, with at least 36 domains combining airline branding with generative-AI flight-search claims; and (9) FIFA World Cup 2026-themed ticket and travel-bundle scams exploiting fan urgency around the tournament, consistent with a broader wave of 13,000+ World Cup-themed domain registrations (roughly 9% malicious/suspicious) tracked industry-wide, including the "Ghost Stadium" cluster of 300+ FIFA-login phishing pages and Android malware families (BTMOB RAT, Massiv, Perseus banking trojans) distributed via fake World Cup streaming/ticketing apps that overlap thematically with the airline-impersonation infrastructure.

BforeAI recorded 400+ domains specifically targeting the high-transaction-value private-jet/charter segment (e.g., privatejetsupport[.]com, charterbookingportal[.]net) and noted a marked acceleration in operational tempo: whereas domain registrations tied to major airline disruptions previously took days to surface, 2026-era threat actors are launching supporting phishing infrastructure within hours of a public incident, timed to align with peak media coverage for higher victim-conversion rates. Newer, higher-cost TLDs (.vip, .luxury, .gold, .app, .live, .shop) are disproportionately used for premium-fraud themes (private aviation, crypto, VIP loyalty), while generic-keyword phishing favors low-cost legacy TLDs (.com, .net, .org). The dataset was produced with a reported false-positive rate below 0.05%, indicating high-confidence detections rather than broad keyword sweeps. No CVE, malware family unique to the airline campaign itself, or specific named threat actor/APT group has been publicly attributed by BforeAI; the activity is characterized as a mix of opportunistic cybercriminal fraud rings and campaign-style, infrastructure-reuse operations rather than a single coordinated actor.

MITRE ATT&CK techniques used in TL-2026-1524

Defense Evasion

T1036 Masquerading

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Execution

T1204 User Execution

Collection

T1213 Data from Information Repositories; T1560 Archive Collected Data

Mobile - Discovery

T1430 Location Tracking

Mobile - Collection

T1512 Video Capture; T1636 Protected User Data

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains

execution

T1610 Deploy Container

Impact

T1657 Financial Theft

Mobile - Initial Access

T1660 Phishing

Mobile - Command and Control

T1663 Remote Access Software

stealth

T1684.001 Impersonation

Affected products and versions in Large-Scale Scam and Impersonation Campaign Targeting

  • LATAM Airlines — Booking/loyalty portal brand
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability
  • Avianca — Booking/loyalty portal brand
    Vulnerable versions: N/A
  • British Airways — Booking/loyalty portal brand, executive/leadership identity
    Vulnerable versions: N/A
  • EasyJet — Booking/loyalty portal brand
    Vulnerable versions: N/A
  • United Airlines — MileagePlus loyalty brand
    Vulnerable versions: N/A
  • Qatar Airways — Booking portal brand, mobile app brand, EOI/vendor portal brand
    Vulnerable versions: N/A
  • Ryanair — Investment/meme-coin brand abuse
    Vulnerable versions: N/A
  • Lufthansa — Trainee/career portal brand (German-language)
    Vulnerable versions: N/A
  • AirAsia — Cargo and betting-themed brand abuse
    Vulnerable versions: N/A
  • IndiGo — Hiring portal brand, crisis support-portal brand, IndigoCoin crypto brand
    Vulnerable versions: N/A

Remediation for Large-Scale Scam and Impersonation Campaign Targeting

Immediate actions

  • Block or sinkhole known malicious domains (indigogoehring[.]com, privatejetsupport[.]com, charterbookingportal[.]net) at DNS/web proxy
  • Enforce multi-person verification for any vendor or charter payment request received via email or web form
  • Alert customer-facing and IT-support staff to fake support-portal lures that surface within hours of publicized service disruptions
  • Add takedown/monitoring coverage for newly registered domains combining airline brand terms with FIFA World Cup 2026 keywords

Workarounds

  • Require customers and employees to navigate only via bookmarked/officially published airline URLs rather than search results or unsolicited links
  • Cross-verify booking, support, and loyalty-program communications against the airline's official app or website before submitting any credentials or payment data

Longer-term hardening

  • Deploy preemptive domain-monitoring (DNS threat intelligence) to detect brand-impersonating and generic travel-keyword domains at registration time, before weaponization
  • Establish a brand-protection/takedown program covering typosquats, homoglyphs, and generic-keyword travel domains across .com/.net/.org/.app/.live/.shop/.vip/.luxury/.gold TLDs
  • Extend preemptive tracking to future high-visibility events (Olympics, summits, major product launches) given demonstrated hours-not-days weaponization speed
  • Run recurring awareness campaigns for customers and employees on AI/LLM-buzzword lures, fake crypto loyalty tokens, and fake job/vendor portals
  • Mandate independent, out-of-band verification of payment or booking-reference requests via officially published phone numbers

Weaknesses (CWE) in Large-Scale Scam and Impersonation Campaign Targeting

CWE-1021, CWE-451, CWE-346

Timeline of Large-Scale Scam and Impersonation Campaign Targeting

  • BforeAI PreCrime Labs begins observation window; suspicious airline-impersonating domain registrations accelerate across the tracked period.
  • End of the September-December 2025 tracking window in which 1,799 airline-brand-specific suspicious domains were identified, part of an 11,600+ domain broader dataset.
  • FIFA World Cup 2026-themed domain registrations surge industry-wide (13,000+ tracked, ~9% malicious/suspicious), overlapping thematically with airline and travel-brand impersonation.
  • BforeAI PreCrime Labs publishes "Commercial Airline Industry Sees Sustained Scam and Impersonation Activity in 2026", detailing 11,600+ malicious/suspicious domains across 35+ airline brands.
  • Help Net Security and TipRanks publish coverage summarizing the BforeAI findings, including CEO Luigi Lenguito's statement that threat actors now stand up supporting phishing infrastructure within hours of a public disruption, versus days in prior years.
  • Campaign distributing the BTMOB Android RAT via fake IPTV/streaming apps offering World Cup 2026 broadcast access is identified by Intel 471, thematically overlapping with airline/travel-branded mobile malware distribution.
  • Researchers identify the "Ghost Stadium" cluster of 300+ phishing pages imitating the FIFA login screen, some loading visuals directly from official FIFA servers to increase credibility.
  • Help Net Security reports cybercriminals have created 19,000 FIFA World Cup 2026-themed domains, reinforcing the event-lure pattern also used against airline brands in the same period.

Sources cited for Large-Scale Scam and Impersonation Campaign Targeting

Threats related to Large-Scale Scam and Impersonation Campaign Targeting

Detection coverage for TL-2026-1524

As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1524 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats