Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU)

Formula 1 Phishing Campaign & Kit Analysis (TL-2026-1944) is a high-severity phishing campaign, first published 2026-08-08. It has no confirmed attribution, affects Formula 1 Official F1 ticketing/hospitality platform (brand and site, maps to 9 MITRE ATT&CK techniques (T1036.005, T1056.003, T1071.001), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-1944

Threat ID
TL-2026-1944
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-08-08
Last reviewed
2026-08-08
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, banking, consumer, hospitality, sports-entertainment
Target regions
Middle East, Europe, Southeast Asia
Detection rules
9
Indicators of compromise
25

Malware and tooling in Formula 1 Phishing Campaign & Kit Analysis

Malware and tooling: Formula 1 Ticketing Phishing Kit

SOCRadar's Threat Research Unit exposed a phishing-as-a-service kit that clones a 134-page Formula 1 ticketing site, uses card-BIN routing to serve bank-specific fake OTP/push/balance-check screens for eight Middle East banks, and relays captured data in real time to a live-operator C2 backend across an 11-domain Cloudflare-hosted cluster.

How Formula 1 Phishing Campaign & Kit Analysis works

SOCRadar's Threat Research Unit (STRU) published a technical breakdown of a phishing kit and campaign that exploits fan demand around Formula 1 Grand Prix events to harvest payment-card data, personal information, and one-time authentication codes. Rather than a generic credential-phishing page, the kit is a high-fidelity, 134-page replica of a legitimate F1 ticketing platform (news, event, entertainment, and hospitality sections included), backed by roughly 40 PHP files split between checkout plumbing and a dedicated fraud-verification module.

The checkout flow walks victims through ticket selection, patron-information capture, and card entry, then pivots to a bank-specific authentication-bypass stage. A BIN-routing component reads the first six digits of the captured card number to identify the issuing bank and serves one of eight pre-built, bank-branded verification screens (Emirates NBD, RAKBANK, HSBC, Abu Dhabi Commercial Bank, Dubai Islamic Bank, Emirates Islamic, First Abu Dhabi Bank, Mashreq). These screens rotate through OTP entry, account-balance verification, push-notification approval, and identification-code pretexts — all designed to walk a real-time human operator through defeating the victim's actual bank MFA at the moment of the (attempted) real transaction, rather than merely harvesting a static password.

The backend polls a command-and-control host at 144.31.3[.]209 over plain HTTP (port 80, `/api/record` endpoint), using flow-control query parameters (`?g=`, `?b=`, `?p=`, `?i=`) on a `secure_check/index.php` handler and a per-victim session cookie so an operator can watch incoming submissions and choose the next screen to serve. A Python utility at `booking/main.py`, containing Russian-language code comments, is used to clone and localize the legitimate site's assets; the kit also embeds a call to Yandex Metrika (`mc.yandex.ru/metrika/tag.js`), a Russian web-analytics platform, on its pages. Neither artifact is a confirmed attribution, but together they are suggestive of Russian-speaking kit developers/operators.

Infrastructure consists of a primary lure domain, f1-tickets-sg[.]com (Singapore-dollar-denominated hospitality pricing, suggesting an APAC-facing lure variant), plus an 11-domain cluster of Spain/Madrid-region-themed lookalikes (`f1-ticket-es[.]com`, `f1-ticket-spain[.]com`, `ticket-f1-es[.]com`, `tickets-f1-es[.]com`, `tickets-f1-spain[.]com`, `booking-f1-spain[.]com`, `f1-tickets-spain[.]com`, `f1-tickets-es[.]com`, `f1-booking-spain[.]com`, `f1-booking-es[.]com`, `ticketsf1-madrid[.]com`), all hosted behind Cloudflare (CLOUDFLARENET ASN) with first-seen registration dates spanning May 20 to July 8, 2026 — roughly two and a half months of active infrastructure expansion. SOCRadar assesses the naming convention (`f1-[ticket|booking]-[region|city]`) as a reliable indicator for hunting future expansion of the same cluster.

Victimology centers on prospective buyers of premium F1 hospitality and grandstand packages — a demographic primed to act quickly during high-intensity ticket-release windows and, per the targeted bank list, concentrated among customers of major UAE/Middle East financial institutions. SOCRadar characterizes the operation as phishing-as-a-service with an actively human-operated fraud layer rather than a fully automated kit, and recommends blocking the identified C2 IP and domain cluster, hunting for the naming pattern, and moving financial-institution fraud controls toward behavior-based detection of balance-check/push-approval requests from non-partnered merchant domains rather than static blacklisting alone.

MITRE ATT&CK techniques used in TL-2026-1944

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1621 Multi-Factor Authentication Request Generation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Execution

T1204.001 User Execution: Malicious Link

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1608.006 SEO Poisoning

Affected products and versions in Formula 1 Phishing Campaign & Kit Analysis

  • Formula 1 — Official F1 ticketing/hospitality platform (brand and site design impersonated by the cloned phishing kit)
  • Emirates NBD — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
  • RAKBANK — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
  • HSBC — Online/mobile banking customers, Middle East operations (impersonated OTP/push/balance verification flow)
  • Abu Dhabi Commercial Bank — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
  • Dubai Islamic Bank — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
  • Emirates Islamic — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
  • First Abu Dhabi Bank — Online/mobile banking customers (impersonated OTP/push/balance verification flow)
  • Mashreq — Online/mobile banking customers (impersonated OTP/push/balance verification flow)

Remediation for Formula 1 Phishing Campaign & Kit Analysis

Immediate actions

  • Block C2 host 144.31.3[.]209 (HTTP, port 80, /api/record endpoint) at the network perimeter and proxy/DNS layer
  • Block the 12 identified phishing domains: f1-tickets-sg[.]com plus the 11-domain cluster (f1-ticket-es[.]com, f1-ticket-spain[.]com, ticket-f1-es[.]com, tickets-f1-es[.]com, tickets-f1-spain[.]com, booking-f1-spain[.]com, f1-tickets-spain[.]com, f1-tickets-es[.]com, f1-booking-spain[.]com, f1-booking-es[.]com, ticketsf1-madrid[.]com)
  • Notify fraud/security teams at the eight impersonated Middle East banks (Emirates NBD, RAKBANK, HSBC, Abu Dhabi Commercial Bank, Dubai Islamic Bank, Emirates Islamic, First Abu Dhabi Bank, Mashreq) of the OTP/balance-check/push-approval phishing pretexts targeting their customers

Workarounds

  • Purchase F1 tickets and hospitality packages only via Formula1.com or its officially appointed agents/promoters
  • Treat any request for an OTP, MFA push approval, or card-balance verification presented mid-checkout as fraudulent — legitimate ticketing platforms never request these

Longer-term hardening

  • Stand up behavior-based domain monitoring for the f1-[ticket|booking]-[region|city] naming convention to catch cluster expansion ahead of victimization
  • Implement fraud-detection triggers for balance-check or push-notification-approval flows initiated from non-partnered, high-risk merchant domains
  • Coordinate with Formula 1 and its appointed ticketing agents on a brand-impersonation takedown workflow for lookalike domains

Timeline of Formula 1 Phishing Campaign & Kit Analysis

  • Earliest identified domain in the related cluster, ticketsf1-madrid[.]com, is registered behind Cloudflare — the first observed piece of the campaign's infrastructure.
  • f1-ticket-spain[.]com is registered the same day as f1-ticket-es[.]com, the latest-dated domain identified in the 11-domain cluster.
  • f1-ticket-es[.]com is registered, part of continued expansion of the Spain/Madrid-themed lookalike domain cluster.
  • SOCRadar recommends immediately blocking C2 host 144.31.3[.]209 and the identified domain cluster, and hunting for the f1-[ticket|booking]-[region|city] naming pattern.
  • SOCRadar's Threat Research Unit (STRU) publishes 'Formula 1 Phishing Campaign & Kit Analysis,' disclosing the cloned ticketing kit, BIN-routed bank-impersonation logic, and C2 infrastructure.
  • TL-Intel Harness ingests the SOCRadar STRU disclosure for detection engineering and corpus correlation.

Sources cited for Formula 1 Phishing Campaign & Kit Analysis

Threats related to Formula 1 Phishing Campaign & Kit Analysis

Detection coverage for TL-2026-1944

As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1944 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats