Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU) — Threadlinqs Intelligence
As of 2026-08-08, Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1944 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
SOCRadar's Threat Research Unit exposed a phishing-as-a-service kit that clones a 134-page Formula 1 ticketing site, uses card-BIN routing to serve bank-specific fake OTP/push/balance-check screens
SOCRadar's Threat Research Unit (STRU) published a technical breakdown of a phishing kit and campaign that exploits fan demand around Formula 1 Grand Prix events to harvest payment-card data, personal information, and one-time authentication codes. Rather than a generic credential-phishing page, the kit is a high-fidelity, 134-page replica of a legitimate F1 ticketing platform (news, event, entertainment, and hospitality sections included), backed by roughly 40 PHP files split between checkout plumbing and a dedicated fraud-verification module.
The checkout flow walks victims through ticket selection, patron-information capture, and card entry, then pivots to a bank-specific authentication-bypass stage. A BIN-routing component reads the first six digits of the captured card number to identify the issuing bank and serves one of eight pre-built, bank-branded verification screens (Emirates NBD, RAKBANK, HSBC, Abu Dhabi Commercial Bank, Dubai Islamic Bank, Emirates Islamic, First Abu Dhabi Bank, Mashreq). These screens rotate through OTP entry, account-balance verification, push-notification approval, and identification-code pretexts — all designed to walk a real-time human operator through defeating the victim's actual bank MFA at the moment of the (attempted) real transaction, rather than merely harvesting a static password.
The backend polls a command-and-control host at 144.31.3[.]209 over plain HTTP (port 80, `/api/record` endpoint), using flow-control query parameters (`?g=`, `?b=`, `?p=`, `?i=`) on a `secure_check/index.php` handler and a per-victim session cookie so an operator can watch incoming submissions and choose the next screen to serve. A Python utility at `booking/main.py`, containing Russian-language code comments, is used to clone and localize the legitimate site's assets; the kit also embeds a call to Yandex Metrika (`mc.yandex.ru/metrika/tag.js`), a Russian web-analytics platform, on its pages. Neither artifact is a confirmed attribution, but together they are suggestive of Russian-speaking kit developers/operators.
Infrastructure consists of a primary lure domain, f1-tickets-sg[.]com (Singapore-dollar-denominated hospitality pricing, suggesting an APAC-facing lure variant), plus an 11-domain cluster of Spain/Madrid-region-themed lookalikes (`f1-ticket-es[.]com`, `f1-ticket-spain[.]com`, `ticket-f1-es[.]com`, `tickets-f1-es[.]com`, `tickets-f1-spain[.]com`, `booking-f1-spain[.]com`, `f1-tickets-spain[.]com`, `f1-tickets-es[.]com`, `f1-booking-spain[.]com`, `f1-booking-es[.]com`, `ticketsf1-madrid[.]com`), all hosted behind Cloudflare (CLOUDFLARENET ASN) with first-seen registration dates spanning May 20 to July 8, 2026 — roughly two and a half months of active infrastructure expansion. SOCRadar assesses the naming convention (`f1-[ticket|booking]-[region|city]`) as a reliable indicator for hunting future expansion of the same cluster.
Victimology centers on prospective buyers of premium F1 hospitality and grandstand packages — a demographic primed to act quickly during high-intensity ticket-release windows and, per the targeted bank list, concentrated among customers of major UAE/Middle East financial institutions. SOCRadar characterizes the operation as phishing-as-a-service with an actively human-operated fraud layer rather than a fully automated kit, and recommends blocking the identified C2 IP and domain cluster, hunting for the naming pattern, and moving financial-institution fraud controls toward behavior-based detection of balance-check/push-approval requests from non-partnered merchant domains rather than static blacklisting alone.
Target sectors: finance, banking, consumer, hospitality, sports-entertainment
Target regions: Middle East, Europe, Southeast Asia
Timeline
- Earliest identified domain in the related cluster, ticketsf1-madrid[.]com, is registered behind Cloudflare — the first observed piece of the campaign's infrastructure.
- f1-ticket-es[.]com is registered, part of continued expansion of the Spain/Madrid-themed lookalike domain cluster.
- f1-ticket-spain[.]com is registered the same day as f1-ticket-es[.]com, the latest-dated domain identified in the 11-domain cluster.
- SOCRadar's Threat Research Unit (STRU) publishes 'Formula 1 Phishing Campaign & Kit Analysis,' disclosing the cloned ticketing kit, BIN-routed bank-impersonation logic, and C2 infrastructure.
- SOCRadar recommends immediately blocking C2 host 144.31.3[.]209 and the identified domain cluster, and hunting for the f1-[ticket|booking]-[region|city] naming pattern.
- TL-Intel Harness ingests the SOCRadar STRU disclosure for detection engineering and corpus correlation.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.006, T1608.006, T1566.002, T1204.001, T1056.003, T1621, T1071.001, T1036.005