Large-Scale Scam and Impersonation Campaign Targeting Commercial Airline Industry (11,600+ Malicious Domains, 35+ Brands)
Large-Scale Scam and Impersonation Campaign Targeting (TL-2026-1524), also tracked as Ghost Stadium (related FIFA World Cup 2026 phishing cluster), is a medium-severity phishing campaign, first published 2026-02-24. It has no confirmed attribution, affects LATAM Airlines Booking/loyalty portal brand, maps to 25 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-1524
- Threat ID
- TL-2026-1524
- Also known as
- Ghost Stadium (related FIFA World Cup 2026 phishing cluster)
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-02-24
- Last reviewed
- 2026-02-24
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- aviation, transport, travel, hospitality, finance
- Target regions
- Global, North America, 005 - South America, Europe, Middle East, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Large-Scale Scam and Impersonation Campaign Targeting
Malware and tooling: BTMOB, Massiv, Perseus
BforeAI PreCrime Labs identified 1,799 suspicious domains registered between September-December 2025 (part of a broader 11,600+ domain dataset) impersonating 35+ global airline brands, deploying phishing booking portals, fake mobile apps, cryptocurrency/meme-coin fraud, fake job/vendor portals, fake support portals, gambling sites, and FIFA World Cup 2026 ticket lures to harvest credentials, PII, and payment data from travelers and airline employees.
How Large-Scale Scam and Impersonation Campaign Targeting works
Between September and December 2025, BforeAI's PreCrime Labs tracked 1,799 suspicious domains directly impersonating 35+ global commercial airline brands -- including LATAM, Avianca, British Airways, EasyJet, United Airlines, Qatar Airways, Ryanair, Lufthansa, AirAsia, IndiGo, Qantas, Batik Air, and Etihad -- as part of a much larger dataset of 11,600+ domains abusing the airline industry across all fraud categories. Roughly 10,000 of those domains used generic travel keywords ("airline", "flight", "charter", "airfare", "private jet") rather than a specific brand name, producing broad, non-targeted phishing infrastructure that casts a wider net than brand-specific attacks and exceeds prior-year totals observed across the entire online travel agency (OTA) industry.
The campaign spans multiple abuse categories operating concurrently: (1) booking-portal and check-in-page phishing that mimics legitimate airline UX to harvest payment card data and PII; (2) loyalty-program and rewards-account phishing using keywords such as "points", "miles", "rewards", and "cards"; (3) cryptocurrency and meme-coin fraud, including fake branded tokens (AirIndiaCoin, IndigoCoin) and fraudulent crypto payment options for flight bookings, several of which were opportunistically spun up around viral industry news (e.g., the Ryanair-vs-SpaceX-CEO public dispute); (4) fake job/recruitment and vendor-onboarding portals using "hiring", "career", "employee", and "partner" language, some password-protected to appear legitimate, soliciting resumes and identity documents from prospective airline employees and contractors; (5) fake customer-support portals stood up during real service disruptions (e.g., IndiGo's flight-cancellation crisis) requesting booking references and payment details under time pressure; (6) gambling/betting sites abusing airline branding and VIP/bonus language (e.g., "WinAirlines Casino" targeting Italian-speaking users, AirAsia betting-themed domains); (7) fake mobile applications distributing malware under airline branding, including Qatar Airways-themed apps used for credential harvesting; (8) AI/LLM-buzzword exploitation, with at least 36 domains combining airline branding with generative-AI flight-search claims; and (9) FIFA World Cup 2026-themed ticket and travel-bundle scams exploiting fan urgency around the tournament, consistent with a broader wave of 13,000+ World Cup-themed domain registrations (roughly 9% malicious/suspicious) tracked industry-wide, including the "Ghost Stadium" cluster of 300+ FIFA-login phishing pages and Android malware families (BTMOB RAT, Massiv, Perseus banking trojans) distributed via fake World Cup streaming/ticketing apps that overlap thematically with the airline-impersonation infrastructure.
BforeAI recorded 400+ domains specifically targeting the high-transaction-value private-jet/charter segment (e.g., privatejetsupport[.]com, charterbookingportal[.]net) and noted a marked acceleration in operational tempo: whereas domain registrations tied to major airline disruptions previously took days to surface, 2026-era threat actors are launching supporting phishing infrastructure within hours of a public incident, timed to align with peak media coverage for higher victim-conversion rates. Newer, higher-cost TLDs (.vip, .luxury, .gold, .app, .live, .shop) are disproportionately used for premium-fraud themes (private aviation, crypto, VIP loyalty), while generic-keyword phishing favors low-cost legacy TLDs (.com, .net, .org). The dataset was produced with a reported false-positive rate below 0.05%, indicating high-confidence detections rather than broad keyword sweeps. No CVE, malware family unique to the airline campaign itself, or specific named threat actor/APT group has been publicly attributed by BforeAI; the activity is characterized as a mix of opportunistic cybercriminal fraud rings and campaign-style, infrastructure-reuse operations rather than a single coordinated actor.
MITRE ATT&CK techniques used in TL-2026-1524
Defense Evasion
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Execution
Collection
T1213 Data from Information Repositories; T1560 Archive Collected Data
Mobile - Discovery
Mobile - Collection
T1512 Video Capture; T1636 Protected User Data
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains
execution
Impact
Mobile - Initial Access
Mobile - Command and Control
stealth
Affected products and versions in Large-Scale Scam and Impersonation Campaign Targeting
- LATAM Airlines — Booking/loyalty portal brand
Vulnerable versions: N/A - brand impersonation, not a software vulnerability - Avianca — Booking/loyalty portal brand
Vulnerable versions: N/A - British Airways — Booking/loyalty portal brand, executive/leadership identity
Vulnerable versions: N/A - EasyJet — Booking/loyalty portal brand
Vulnerable versions: N/A - United Airlines — MileagePlus loyalty brand
Vulnerable versions: N/A - Qatar Airways — Booking portal brand, mobile app brand, EOI/vendor portal brand
Vulnerable versions: N/A - Ryanair — Investment/meme-coin brand abuse
Vulnerable versions: N/A - Lufthansa — Trainee/career portal brand (German-language)
Vulnerable versions: N/A - AirAsia — Cargo and betting-themed brand abuse
Vulnerable versions: N/A - IndiGo — Hiring portal brand, crisis support-portal brand, IndigoCoin crypto brand
Vulnerable versions: N/A
Remediation for Large-Scale Scam and Impersonation Campaign Targeting
Immediate actions
- Block or sinkhole known malicious domains (indigogoehring[.]com, privatejetsupport[.]com, charterbookingportal[.]net) at DNS/web proxy
- Enforce multi-person verification for any vendor or charter payment request received via email or web form
- Alert customer-facing and IT-support staff to fake support-portal lures that surface within hours of publicized service disruptions
- Add takedown/monitoring coverage for newly registered domains combining airline brand terms with FIFA World Cup 2026 keywords
Workarounds
- Require customers and employees to navigate only via bookmarked/officially published airline URLs rather than search results or unsolicited links
- Cross-verify booking, support, and loyalty-program communications against the airline's official app or website before submitting any credentials or payment data
Longer-term hardening
- Deploy preemptive domain-monitoring (DNS threat intelligence) to detect brand-impersonating and generic travel-keyword domains at registration time, before weaponization
- Establish a brand-protection/takedown program covering typosquats, homoglyphs, and generic-keyword travel domains across .com/.net/.org/.app/.live/.shop/.vip/.luxury/.gold TLDs
- Extend preemptive tracking to future high-visibility events (Olympics, summits, major product launches) given demonstrated hours-not-days weaponization speed
- Run recurring awareness campaigns for customers and employees on AI/LLM-buzzword lures, fake crypto loyalty tokens, and fake job/vendor portals
- Mandate independent, out-of-band verification of payment or booking-reference requests via officially published phone numbers
Weaknesses (CWE) in Large-Scale Scam and Impersonation Campaign Targeting
CWE-1021, CWE-451, CWE-346
Timeline of Large-Scale Scam and Impersonation Campaign Targeting
- BforeAI PreCrime Labs begins observation window; suspicious airline-impersonating domain registrations accelerate across the tracked period.
- End of the September-December 2025 tracking window in which 1,799 airline-brand-specific suspicious domains were identified, part of an 11,600+ domain broader dataset.
- FIFA World Cup 2026-themed domain registrations surge industry-wide (13,000+ tracked, ~9% malicious/suspicious), overlapping thematically with airline and travel-brand impersonation.
- BforeAI PreCrime Labs publishes "Commercial Airline Industry Sees Sustained Scam and Impersonation Activity in 2026", detailing 11,600+ malicious/suspicious domains across 35+ airline brands.
- Help Net Security and TipRanks publish coverage summarizing the BforeAI findings, including CEO Luigi Lenguito's statement that threat actors now stand up supporting phishing infrastructure within hours of a public disruption, versus days in prior years.
- Campaign distributing the BTMOB Android RAT via fake IPTV/streaming apps offering World Cup 2026 broadcast access is identified by Intel 471, thematically overlapping with airline/travel-branded mobile malware distribution.
- Researchers identify the "Ghost Stadium" cluster of 300+ phishing pages imitating the FIFA login screen, some loading visuals directly from official FIFA servers to increase credibility.
- Help Net Security reports cybercriminals have created 19,000 FIFA World Cup 2026-themed domains, reinforcing the event-lure pattern also used against airline brands in the same period.
Sources cited for Large-Scale Scam and Impersonation Campaign Targeting
- Commercial Airline Industry Sees Sustained Scam and Impersonation Activity in 2026
- Airline brands become launchpads for phishing, crypto fraud
- BforeAI Highlights Rising Airline-Focused Cyber Threat Activity
- Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup
- World Cup 2026: how to avoid ticket scams and fake sites
- FBI warns of fake FIFA World Cup 2026 ticket sites stealing fan data
- World Cup 2026 Scams: Fake Tickets & FIFA Sites
- Active Exploitation Alert: FIFA World Cup 2026 Targeted by Fake Ticket Sites, Banking Malware, and Credential Theft
- FIFA World Cup 2026 Ticket Scams: How to Spot Fake Tickets and QR Codes
Threats related to Large-Scale Scam and Impersonation Campaign Targeting
Detection coverage for TL-2026-1524
As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1524 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.