FIFA World Cup 2026 Fraud Ecosystem: GHOST STADIUM Phishing, Mass Typosquatting, and Vidar/Lumma Infostealer Credential Theft

FIFA World Cup 2026 Fraud Ecosystem (TL-2026-1573), also tracked as Ghost Stadium Fraud Campaign, is a high-severity fraud campaign, first published 2026-07-20. It is attributed to GHOST STADIUM with medium confidence, affects FIFA fifa.com / fifa.org ticketing, hospitality, and SSO platforms, maps to 20 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 39 indicators of compromise.

Key facts for TL-2026-1573

Threat ID
TL-2026-1573
Also known as
Ghost Stadium Fraud Campaign, FIFA World Cup 2026 Fraud Ecosystem
Severity
HIGH
Status
ACTIVE
Category
FRAUD
First published
2026-07-20
Last reviewed
2026-07-20
Attribution
GHOST STADIUM
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
sports entertainment, hospitality, ticketing, e-commerce retail, broadcasting streaming, gambling betting, financial services, end users consumers
Target regions
Global, North America, Latin America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
39

Malware and tooling in FIFA World Cup 2026 Fraud Ecosystem

Malware and tooling: HijackLoader, Lumma, RedLine, Stealc, Vidar, Layui 2.7.6

A sprawling, multi-actor fraud ecosystem is exploiting the 2026 FIFA World Cup: 4,300+ lookalike/typosquat domains (SOCRadar counts 1,100+ 'World Cup' domains and 600+ FIFA typosquats; Group-IB's GHOST STADIUM tracking shows 300+ live phishing domains and 3,800+ parked since August 2025), a Chinese-speaking operator's pixel-perfect PingIdentity-SSO-cloning phishing kit, and Vidar/Lumma-dominated infostealer pipelines feeding 130,000+ dark-web credential logs (2,500+ confirmed FIFA account pairs). The FBI IC3 issued PSA I-052726-PSA on 2026-05-27 naming 43 fraudulent FIFA-spoofing domains.

How FIFA World Cup 2026 Fraud Ecosystem works

Multiple independent research teams (SOCRadar, Group-IB, Cyble, Flare, Rescana, the FBI's IC3) have converged on the same finding: the 2026 FIFA World Cup has produced an unprecedented, professionalized cybercrime ecosystem spanning six parallel fraud schemes operated by at least four distinct threat clusters. The most developed cluster, tracked by Group-IB as GHOST STADIUM, is attributed with medium-high confidence to a Chinese-speaking, financially motivated operator based on Chinese-language source code comments, use of the Layui 2.7.6 Chinese open-source UI framework, and locale auto-detection covering Simplified, Traditional, and Hong Kong Chinese alongside 8+ other languages. GHOST STADIUM has registered 4,300+ domains since August 2025 (300+ live, 3,800+ parked/pre-positioned for activation near kickoff), sharing infrastructure fingerprints across the cluster: identical Tawk.to live-chat property ID, three shared Meta Pixel advertising IDs, shared SSL certificates, and 14 hosting IP nodes. The flagship phishing kit is a custom React single-page application that pixel-perfect clones fifa.com, including a functional clone of FIFA's real PingIdentity SSO login flow (reusing FIFA's actual client_id) and a password-reset function that locks victims out post-capture and redirects them to the legitimate FIFA site to reduce suspicion. Six fraud schemes run in parallel: (1) SSO credential phishing, (2) fake premium/hospitality ticket sales estimated at $71-474M in losses alone, (3) counterfeit merchandise storefronts (56+ domains) with Telegram sales channels, (4) fraudulent streaming platforms (55+ domains), (5) fake betting/casino sites (32+ domains), and (6) infostealer-driven mass credential theft. Payment monetization spans direct card capture, third-party payment gateways (pay.zfxupi.net), peer-to-peer cashout (Chime, Nequi), Mexico-specific payment rails (FIXYD), and crypto on-ramps (Alchemy Pay to USDT via Binance Smart Chain), indicating a mature, well-funded money-laundering operation. Separately, Flare Systems documents an infostealer supply chain feeding this credential-theft economy: victims searching for pirated/cracked software (e.g., free PDF editors) are funneled through disposable .cfd redirector domains to fake Google Drive download pages serving a ZIP that DLL-sideloads a trojanized SDL3.dll into a renamed, legitimate Steam binary (HijackLoader/Rugmi), ultimately deploying Lumma Stealer via reflective, largely fileless in-memory execution with a second stage steganographically hidden inside PNG IDAT chunks. Across April 2025-April 2026, Flare identified nearly 130,000 infostealer logs referencing FIFA-related credentials (Vidar 67%, Lumma 24%, StealC 5%, RedLine 3%, Nexus/Aurora 1% each), with 2,500+ confirmed exposed email/password pairs split across fifa.com and fifa.org. Compromised staff, partner, or vendor credentials create a pivot path into FIFA's operational/ticketing backend and SSO infrastructure. The FBI's Internet Crime Complaint Center corroborated the domain-spoofing threat independently, issuing PSA I-052726-PSA on 2026-05-27 (alert number I-052726-PSA) naming 43 fraudulent domains using typosquatting (fiffa.com), alternative TLDs (fifa.cab, fifa.pink, fifa.blue, fifa.pub, fifa.beer, fifa.click), and subdomain impersonation (jobs-fifa.com, fifa-hr.com, fifa-hiring.com) for credential harvesting and counterfeit ticket sales. Given the ~150 million ticket requests logged in the first 14 days of the sales window, the operation exploits acute urgency and scarcity to drive victims past normal diligence.

MITRE ATT&CK techniques used in TL-2026-1573

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1574 Hijack Execution Flow; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Command and Control

T1102 Web Service

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Execution

T1204 User Execution

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains

reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

Affected products and versions in FIFA World Cup 2026 Fraud Ecosystem

  • FIFA — fifa.com / fifa.org ticketing, hospitality, and SSO platforms
    Vulnerable versions: all public-facing ticketing/hospitality/SSO web properties
  • Multiple — World Cup hospitality, ticketing, merchandise, and streaming vendors (third parties)
    Vulnerable versions: staff/vendor credentials and SSO sessions
  • Valve — Steam client binary (abused via DLL side-loading in the infostealer pipeline)
    Vulnerable versions: legitimate Steam binary renamed and bundled with trojanized SDL3.dll

Remediation for FIFA World Cup 2026 Fraud Ecosystem

Immediate actions

  • Type fifa.com directly into the browser address bar; never follow sponsored/search-ad or social-media links to World Cup ticketing sites
  • Reject any FIFA ticket, merchandise, streaming, or betting offer that requires cryptocurrency payment or peer-to-peer cashapp transfer
  • Enable MFA on all FIFA.com/FIFA.org accounts, corporate SSO, and any linked email/payment accounts before the pre-tournament and tournament windows
  • Report suspected fraudulent domains and financial losses to the FBI IC3 at ic3.gov with domain, interaction, and transaction details

Workarounds

  • Use bookmarked/saved links for FIFA login pages instead of search engine results or paid ads
  • Verify all World Cup ticket, merchandise, streaming, and betting purchases are made exclusively through fifa.com or officially licensed partners

Longer-term hardening

  • Continuously monitor for corporate/vendor/staff domains and email addresses appearing in Vidar/Lumma/StealC/RedLine infostealer logs
  • Deploy EDR detections for HijackLoader/Rugmi DLL side-loading via renamed legitimate binaries (e.g., Steam) and reflective in-memory payload execution
  • Brand-monitor for newly registered typosquat/lookalike FIFA and World Cup domains (alt-TLD, hyphenation, host-city combinations) and pursue rapid takedown
  • Audit third-party hospitality, ticketing, merchandise, and streaming vendors for SSO/session-token exposure given the credential-pivot risk into operational backends

Timeline of FIFA World Cup 2026 Fraud Ecosystem

  • Flare Systems' infostealer-log dataset referencing FIFA-related credentials begins (April 2025-April 2026 collection window), ultimately yielding ~130,000 logs (Vidar 67%, Lumma 24%, StealC 5%, RedLine 3%, Nexus/Aurora 1% each) and 2,500+ confirmed fifa.com/fifa.org email-password pairs.
  • GHOST STADIUM cluster begins registering fraudulent FIFA-themed domains; Group-IB tracks 4,300+ registrations from this point through May 2026, with most held dormant/parked for later activation.
  • SOCRadar observes a new wave of 260 domains pairing FIFA branding with host-city names, registered since April 2026, alongside 1,100+ generic 'World Cup' domains and 600+ FIFA typosquats.
  • Reporting discloses 2,500+ confirmed FIFA account credential pairs actively trading on dark-web markets at $5-$50 per pair, sourced from an estimated 130,000-170,000 infostealer logs referencing FIFA.
  • Group-IB publishes the GHOST STADIUM report detailing 300+ live phishing domains, 3,800+ parked domains, a PingIdentity SSO-cloning phishing kit, and six parallel fraud schemes with potential losses in the billions.
  • The FBI's Internet Crime Complaint Center issues PSA I-052726-PSA, naming 43 fraudulent domains spoofing fifa.com via typosquatting, alternative TLDs, and subdomain impersonation (jobs-fifa.com, fifa-hr.com).
  • Over 150 million ticket requests are logged in the first 14 days of the World Cup ticket sales window, creating acute urgency and scarcity that the fraud ecosystem exploits to pressure victims.
  • TL-Intel Harness RESEARCH phase compiles cross-source analysis of the FIFA World Cup 2026 fraud ecosystem from SOCRadar, Group-IB, Cyble, Flare, Rescana, and FBI IC3 reporting.

Sources cited for FIFA World Cup 2026 Fraud Ecosystem

Threats related to FIFA World Cup 2026 Fraud Ecosystem

Detection coverage for TL-2026-1573

As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1573 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats