GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs — Threadlinqs Intelligence
As of 2026-07-30, GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs is a high-severity phishing threat attributed to Ghost Stadium (CN), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1768 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Ghost Stadium · CN · FINANCIAL
Trend Micro tracked 35,538 malicious or suspicious FIFA/World-Cup-themed sites (Jan-Jun 2026, ~1.48M visits from Japan alone); within that wave, Group-IB independently identified a single cluster it
Between January and June 2026, Trend Micro's TrendAI telemetry flagged 35,538 malicious or suspicious websites containing the keywords "fifa" or "worldcup," drawing an estimated 1.48 million visits from Japan alone and likely far more globally. Within that broader wave of World Cup-themed counterfeit-merchandise shops, fake streaming portals, and fraudulent betting sites, a single cluster that Group-IB independently named GHOST STADIUM (public disclosure 2026-05-27) stands out for its technical sophistication and financial impact: a custom React single-page-application phishing kit, built on the Chinese open-source Layui 2.7.6 UI framework, deployed byte-for-byte identically across 300+ of more than 4,300 FIFA-themed domains registered since August 2025.
The kit reproduces fifa.com's real ticketing login flow to near pixel-perfect fidelity, including a functioning clone of FIFA's PingIdentity-backed single sign-on that embeds the genuine production OAuth client_id (35072598-fc20-4142-a469-1b940db47e6f) copied verbatim from the live service, complete with a "_p1:reset:userPassword_" scope parameter that lets the kit trigger password resets after credential capture. Victim-facing branding and product imagery are pulled live from FIFA's own CDN, defeating automated content-similarity phishing detectors that expect cloned assets to be locally hosted. After a victim submits card data and a one-time password, the kit's back end relays the transaction in real time - behaving as an adversary-in-the-middle that pushes the fraudulent charge through before the OTP expires, which is why multi-factor authentication does not stop the fraud - then silently redirects the browser to the real https://www.fifa.com/auth/ endpoint to delay victim suspicion.
Infrastructure analysis by Group-IB, independently corroborated by Validin, shows heavy automation: near-identical ~415 KB HTML payloads, 300+ domains sharing a small set of TLS certificate fingerprints and Meta Pixel tracking IDs, over half the cluster registered through a single registrar (GNAME.COM PTE. LTD.), and traffic driven primarily through Facebook ad campaigns using countdown-timer discount lures, with secondary funneling via Telegram/WhatsApp "Call now" buttons and organic search-engine-poisoning placement. A shared Tawk.to live-chat widget ID appears across the 79 domains focused on premium/hospitality tickets ($1,500-$10,000+ face value), where extrapolated victim counts alone could exceed 47,400 people and $71-474 million in losses; Group-IB estimates total losses across all GHOST STADIUM tiers could reach into the billions. Stolen funds are cashed out through diversified rails: direct card capture, a third-party payment gateway (pay.zfxupi.net), P2P apps (Chime cashtag $Paramjit-Bains, Nequi account 3202059757), a Mexico-specific rail (FIXYD), and the ChainUGO crypto on-ramp (testnet.chainugo.com), which converts stolen USD into USDT on Binance Smart Chain.
Chinese-language source-code comments, exclusive use of the Layui framework (virtually unknown outside Chinese developer circles), and locale handling that separately distinguishes Simplified, Traditional, and Hong Kong Chinese are the primary signals behind the "Chinese-speaking, financially motivated" attribution; there is no evidence of nation-state sponsorship, so this is tracked as a criminal actor rather than a state-backed one. Group-IB frames GHOST STADIUM as one of at least four independent threat actors and six distinct fraud schemes operating in the same World Cup 2026 fraud ecosystem - alongside a bulk domain-squatter, a phishing-kit-as-a-service supplier, and infostealer operators distributing Vidar and Lumma, whose logs have already surfaced roughly 170,000 FIFA-referencing infections and at least 2,513 FIFA account credential pairs for sale on dark-web markets at $5-$50 per pair. The campaign remains active through the tournament window (2026-06-11 to 2026-07-19) and beyond, with roughly 3,800 additional pre
Target sectors: consumer, sports-entertainment, financial-services, retail-ecommerce
Target regions: Global, japan, North America, mexico, colombia
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1593.002, T1594, T1583.001, T1583.004, T1585.001, T1608.001, T1588.002, T1608.006, T1566.002, T1566.003