Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU)
Formula 1 Phishing Campaign & Kit Analysis (TL-2026-1944) is a high-severity phishing campaign, first published 2026-08-08. It has no confirmed attribution, affects Formula 1 Official F1 ticketing/hospitality platform (brand and site, maps to 9 MITRE ATT&CK techniques (T1036.005, T1056.003, T1071.001), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-1944
- Threat ID
- TL-2026-1944
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-08
- Last reviewed
- 2026-08-08
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, banking, consumer, hospitality, sports-entertainment
- Target regions
- Middle East, Europe, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Formula 1 Phishing Campaign & Kit Analysis
Malware and tooling: Formula 1 Ticketing Phishing Kit
SOCRadar's Threat Research Unit exposed a phishing-as-a-service kit that clones a 134-page Formula 1 ticketing site, uses card-BIN routing to serve bank-specific fake OTP/push/balance-check screens for eight Middle East banks, and relays captured data in real time to a live-operator C2 backend across an 11-domain Cloudflare-hosted cluster.
How Formula 1 Phishing Campaign & Kit Analysis works
SOCRadar's Threat Research Unit (STRU) published a technical breakdown of a phishing kit and campaign that exploits fan demand around Formula 1 Grand Prix events to harvest payment-card data, personal information, and one-time authentication codes. Rather than a generic credential-phishing page, the kit is a high-fidelity, 134-page replica of a legitimate F1 ticketing platform (news, event, entertainment, and hospitality sections included), backed by roughly 40 PHP files split between checkout plumbing and a dedicated fraud-verification module.
The checkout flow walks victims through ticket selection, patron-information capture, and card entry, then pivots to a bank-specific authentication-bypass stage. A BIN-routing component reads the first six digits of the captured card number to identify the issuing bank and serves one of eight pre-built, bank-branded verification screens (Emirates NBD, RAKBANK, HSBC, Abu Dhabi Commercial Bank, Dubai Islamic Bank, Emirates Islamic, First Abu Dhabi Bank, Mashreq). These screens rotate through OTP entry, account-balance verification, push-notification approval, and identification-code pretexts — all designed to walk a real-time human operator through defeating the victim's actual bank MFA at the moment of the (attempted) real transaction, rather than merely harvesting a static password.
The backend polls a command-and-control host at 144.31.3[.]209 over plain HTTP (port 80, `/api/record` endpoint), using flow-control query parameters (`?g=`, `?b=`, `?p=`, `?i=`) on a `secure_check/index.php` handler and a per-victim session cookie so an operator can watch incoming submissions and choose the next screen to serve. A Python utility at `booking/main.py`, containing Russian-language code comments, is used to clone and localize the legitimate site's assets; the kit also embeds a call to Yandex Metrika (`mc.yandex.ru/metrika/tag.js`), a Russian web-analytics platform, on its pages. Neither artifact is a confirmed attribution, but together they are suggestive of Russian-speaking kit developers/operators.
Infrastructure consists of a primary lure domain, f1-tickets-sg[.]com (Singapore-dollar-denominated hospitality pricing, suggesting an APAC-facing lure variant), plus an 11-domain cluster of Spain/Madrid-region-themed lookalikes (`f1-ticket-es[.]com`, `f1-ticket-spain[.]com`, `ticket-f1-es[.]com`, `tickets-f1-es[.]com`, `tickets-f1-spain[.]com`, `booking-f1-spain[.]com`, `f1-tickets-spain[.]com`, `f1-tickets-es[.]com`, `f1-booking-spain[.]com`, `f1-booking-es[.]com`, `ticketsf1-madrid[.]com`), all hosted behind Cloudflare (CLOUDFLARENET ASN) with first-seen registration dates spanning May 20 to July 8, 2026 — roughly two and a half months of active infrastructure expansion. SOCRadar assesses the naming convention (`f1-[ticket|booking]-[region|city]`) as a reliable indicator for hunting future expansion of the same cluster.
Victimology centers on prospective buyers of premium F1 hospitality and grandstand packages — a demographic primed to act quickly during high-intensity ticket-release windows and, per the targeted bank list, concentrated among customers of major UAE/Middle East financial institutions. SOCRadar characterizes the operation as phishing-as-a-service with an actively human-operated fraud layer rather than a fully automated kit, and recommends blocking the identified C2 IP and domain cluster, hunting for the naming pattern, and moving financial-institution fraud controls toward behavior-based detection of balance-check/push-approval requests from non-partnered merchant domains rather than static blacklisting alone.
MITRE ATT&CK techniques used in TL-2026-1944
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Credential Access
T1056.003 Input Capture: Web Portal Capture; T1621 Multi-Factor Authentication Request Generation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Execution
T1204.001 User Execution: Malicious Link
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1608.006 SEO Poisoning
Affected products and versions in Formula 1 Phishing Campaign & Kit Analysis
- Formula 1 — Official F1 ticketing/hospitality platform (brand and site design impersonated by the cloned phishing kit)
- Emirates NBD — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
- RAKBANK — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
- HSBC — Online/mobile banking customers, Middle East operations (impersonated OTP/push/balance verification flow)
- Abu Dhabi Commercial Bank — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
- Dubai Islamic Bank — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
- Emirates Islamic — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
- First Abu Dhabi Bank — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
- Mashreq — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
Remediation for Formula 1 Phishing Campaign & Kit Analysis
Immediate actions
- Block C2 host 144.31.3[.]209 (HTTP, port 80, /api/record endpoint) at the network perimeter and proxy/DNS layer
- Block the 12 identified phishing domains: f1-tickets-sg[.]com plus the 11-domain cluster (f1-ticket-es[.]com, f1-ticket-spain[.]com, ticket-f1-es[.]com, tickets-f1-es[.]com, tickets-f1-spain[.]com, booking-f1-spain[.]com, f1-tickets-spain[.]com, f1-tickets-es[.]com, f1-booking-spain[.]com, f1-booking-es[.]com, ticketsf1-madrid[.]com)
- Notify fraud/security teams at the eight impersonated Middle East banks (Emirates NBD, RAKBANK, HSBC, Abu Dhabi Commercial Bank, Dubai Islamic Bank, Emirates Islamic, First Abu Dhabi Bank, Mashreq) of the OTP/balance-check/push-approval phishing pretexts targeting their customers
Workarounds
- Purchase F1 tickets and hospitality packages only via Formula1.com or its officially appointed agents/promoters
- Treat any request for an OTP, MFA push approval, or card-balance verification presented mid-checkout as fraudulent — legitimate ticketing platforms never request these
Longer-term hardening
- Stand up behavior-based domain monitoring for the f1-[ticket|booking]-[region|city] naming convention to catch cluster expansion ahead of victimization
- Implement fraud-detection triggers for balance-check or push-notification-approval flows initiated from non-partnered, high-risk merchant domains
- Coordinate with Formula 1 and its appointed ticketing agents on a brand-impersonation takedown workflow for lookalike domains
Timeline of Formula 1 Phishing Campaign & Kit Analysis
- Earliest identified domain in the related cluster, ticketsf1-madrid[.]com, is registered behind Cloudflare — the first observed piece of the campaign's infrastructure.
- f1-ticket-spain[.]com is registered the same day as f1-ticket-es[.]com, the latest-dated domain identified in the 11-domain cluster.
- f1-ticket-es[.]com is registered, part of continued expansion of the Spain/Madrid-themed lookalike domain cluster.
- SOCRadar recommends immediately blocking C2 host 144.31.3[.]209 and the identified domain cluster, and hunting for the f1-[ticket|booking]-[region|city] naming pattern.
- SOCRadar's Threat Research Unit (STRU) publishes 'Formula 1 Phishing Campaign & Kit Analysis,' disclosing the cloned ticketing kit, BIN-routed bank-impersonation logic, and C2 infrastructure.
- TL-Intel Harness ingests the SOCRadar STRU disclosure for detection engineering and corpus correlation.
Sources cited for Formula 1 Phishing Campaign & Kit Analysis
- Formula 1 Phishing Campaign & Kit Analysis
- Threat Actors Attacking Fans and Teams of Belgian Grand Prix With Phishing Campaigns
- Phishing Attacks Hit Fans and Teams of the Belgian Grand Prix
- Fake Streams, Counterfeit Merch & Scams: How Fraudsters Target F1 Fans
- Formula 1 fans targeted by evolving scams, Bitdefender warns
- Grand Prix website hacked to send out phishing emails to F1 fans
- 7 Formula 1 Scams That Are Catching Out Fans Right Now
Threats related to Formula 1 Phishing Campaign & Kit Analysis
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)
- Zscaler ThreatLabz 2026 Phishing Report: Volume Falls 20% as AI Trades Mass Spam for Targeted, Higher-Conversion Credential & Session-Theft Campaigns
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs
Detection coverage for TL-2026-1944
As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1944 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.