Large-Scale Scam and Impersonation Campaign Targeting Commercial Airline Industry (11,600+ Malicious Domains, 35+ Brands) — Threadlinqs Intelligence
As of 2026-02-24, Large-Scale Scam and Impersonation Campaign Targeting Commercial Airline Industry (11,600+ Malicious Domains, 35+ Brands) is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1524 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
BforeAI PreCrime Labs identified 1,799 suspicious domains registered between September-December 2025 (part of a broader 11,600+ domain dataset) impersonating 35+ global airline brands, deploying
Between September and December 2025, BforeAI's PreCrime Labs tracked 1,799 suspicious domains directly impersonating 35+ global commercial airline brands -- including LATAM, Avianca, British Airways, EasyJet, United Airlines, Qatar Airways, Ryanair, Lufthansa, AirAsia, IndiGo, Qantas, Batik Air, and Etihad -- as part of a much larger dataset of 11,600+ domains abusing the airline industry across all fraud categories. Roughly 10,000 of those domains used generic travel keywords ("airline", "flight", "charter", "airfare", "private jet") rather than a specific brand name, producing broad, non-targeted phishing infrastructure that casts a wider net than brand-specific attacks and exceeds prior-year totals observed across the entire online travel agency (OTA) industry.
The campaign spans multiple abuse categories operating concurrently: (1) booking-portal and check-in-page phishing that mimics legitimate airline UX to harvest payment card data and PII; (2) loyalty-program and rewards-account phishing using keywords such as "points", "miles", "rewards", and "cards"; (3) cryptocurrency and meme-coin fraud, including fake branded tokens (AirIndiaCoin, IndigoCoin) and fraudulent crypto payment options for flight bookings, several of which were opportunistically spun up around viral industry news (e.g., the Ryanair-vs-SpaceX-CEO public dispute); (4) fake job/recruitment and vendor-onboarding portals using "hiring", "career", "employee", and "partner" language, some password-protected to appear legitimate, soliciting resumes and identity documents from prospective airline employees and contractors; (5) fake customer-support portals stood up during real service disruptions (e.g., IndiGo's flight-cancellation crisis) requesting booking references and payment details under time pressure; (6) gambling/betting sites abusing airline branding and VIP/bonus language (e.g., "WinAirlines Casino" targeting Italian-speaking users, AirAsia betting-themed domains); (7) fake mobile applications distributing malware under airline branding, including Qatar Airways-themed apps used for credential harvesting; (8) AI/LLM-buzzword exploitation, with at least 36 domains combining airline branding with generative-AI flight-search claims; and (9) FIFA World Cup 2026-themed ticket and travel-bundle scams exploiting fan urgency around the tournament, consistent with a broader wave of 13,000+ World Cup-themed domain registrations (roughly 9% malicious/suspicious) tracked industry-wide, including the "Ghost Stadium" cluster of 300+ FIFA-login phishing pages and Android malware families (BTMOB RAT, Massiv, Perseus banking trojans) distributed via fake World Cup streaming/ticketing apps that overlap thematically with the airline-impersonation infrastructure.
BforeAI recorded 400+ domains specifically targeting the high-transaction-value private-jet/charter segment (e.g., privatejetsupport[.]com, charterbookingportal[.]net) and noted a marked acceleration in operational tempo: whereas domain registrations tied to major airline disruptions previously took days to surface, 2026-era threat actors are launching supporting phishing infrastructure within hours of a public incident, timed to align with peak media coverage for higher victim-conversion rates. Newer, higher-cost TLDs (.vip, .luxury, .gold, .app, .live, .shop) are disproportionately used for premium-fraud themes (private aviation, crypto, VIP loyalty), while generic-keyword phishing favors low-cost legacy TLDs (.com, .net, .org). The dataset was produced with a reported false-positive rate below 0.05%, indicating high-confidence detections rather than broad keyword sweeps. No CVE, malware family unique to the airline campaign itself, or specific named threat actor/APT group has been publicly attributed by BforeAI; the activity is characterized as a mix of opportunistic cybercriminal fraud rings and campaign-style, infrastructure-reuse operations rather than a single coordinated actor.
Weaknesses (CWE)
CWE-1021, CWE-451, CWE-346
Target sectors: aviation, transport, travel, hospitality, finance
Target regions: Global, North America, 005 - South America, Europe, Middle East, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1591, T1593, T1583, T1583, T1587, T1585, T1584, T1608, T1566, T1566