GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans
Key Takeaways A sophisticated and financially motivated phishing campaign, dubbed “GHOST STADIUM,” is actively targeting FIFA World Cup fans. The operation leverages over 300 fake...
Key Takeaways
- A sophisticated and financially motivated phishing campaign, dubbed “GHOST STADIUM,” is actively targeting FIFA World Cup fans.
- The operation leverages over 300 fake domains, impersonating official FIFA platforms to steal credentials, sell fake tickets, and distribute malware.
- Multiple fraud schemes are running concurrently, making this a complex and pervasive threat.
- Financial losses from this campaign could amount to billions of dollars, with thousands of legitimate FIFA account credentials already compromised.
Widespread Fraud Targets FIFA World Cup 2026 Fans with “GHOST STADIUM” Phishing
As anticipation builds for the 2026 FIFA World Cup, cybercriminals are unleashing a highly organized and expansive fraud operation designed to exploit the global fervor. Security researchers have identified a massive phishing campaign, codenamed “GHOST STADIUM,” which has deployed more than 300 fraudulent domains to ensnare unsuspecting football enthusiasts.
Table Of Content
- Key Takeaways
- Widespread Fraud Targets FIFA World Cup 2026 Fans with “GHOST STADIUM” Phishing
- Exploiting Unprecedented Demand for Tickets
- The GHOST STADIUM Threat Actor
- GHOST STADIUM Phishing Campaign Mechanics
- Infostealer Threat and Protective Steps
- What You Should Do
- Indicators of Compromise (IoCs):-
This meticulously crafted scheme is not only sophisticated but also exceptionally well-resourced, capable of deceiving even vigilant internet users. With the immense financial stakes surrounding the World Cup, this campaign represents one of the most significant cyber threats ever linked to a major sporting event.
Exploiting Unprecedented Demand for Tickets
The core of the “GHOST STADIUM” campaign capitalizes on the overwhelming demand for tickets to the FIFA World Cup 2026, which will be hosted across the United States, Canada, and Mexico. The initial two weeks of the ticket sales window saw over 150 million requests, creating a fertile ground for scammers to exploit the urgency and desperation of fans.
Fraudsters have established an extensive network of bogus websites, meticulously designed to mimic official FIFA platforms. Victims navigating to these sites often find it nearly impossible to distinguish them from legitimate sources, making them highly effective traps.
According to a report by Group-IB, shared with Cyber Security News (CSN), researchers have uncovered six distinct fraud methodologies, identified four independent threat actors, and pinpointed over 3,500 deceptive domains impersonating FIFA’s online presence.
The GHOST STADIUM Threat Actor
At the heart of this sprawling operation is a Chinese-speaking, financially driven threat actor known as GHOST STADIUM. This entity is orchestrating a coordinated phishing campaign across more than 300 domains, with potential financial losses from this single campaign estimated to reach into the billions.
The operation encompasses a diverse array of six parallel fraud schemes, each employing a different tactic to target football fans. These include:
- Credential phishing to steal login information.
- Fraudulent ticket sales.
- Online storefronts selling counterfeit merchandise.
- Deceptive streaming platforms.
- Bogus betting websites.
- Credential theft driven by infostealer malware.
Each of these schemes utilizes its own monetization strategy, complicating efforts to dismantle the entire operation through a singular takedown. Collectively, they form a rapidly expanding fraud ecosystem that is intensifying as the tournament draws nearer.
Already, over 2,513 confirmed FIFA account credential pairs are being traded on dark web markets, with prices ranging from $5 to $50 per pair. These credentials were not primarily acquired through targeted phishing but rather as incidental captures by broad infostealer campaigns, predominantly involving the Vidar and Lumma malware families.
Approximately 170,000 infostealer logs containing FIFA-related references have been identified, underscoring the vast scale of credential theft well in advance of the World Cup’s commencement.
GHOST STADIUM Phishing Campaign Mechanics
The GHOST STADIUM phishing kit is a custom-built, React-based single-page application that achieves an almost pixel-perfect replication of the official FIFA website. It is constructed using the Layui 2.7.6 framework, a Chinese UI library largely unknown outside of the Chinese developer community.
The kit faithfully mimics FIFA’s PingIdentity Single Sign-On (SSO) login process, leveraging a genuine client_id directly extracted from the actual FIFA SSO. Upon successful credential theft, the kit immediately initiates a password reset function to lock victims out of their accounts. Following this, it silently redirects them to the legitimate FIFA website, making the attack appear as a successful login attempt.
The phishing kit features automatic browser language detection, adapting its interface across 11 languages, including three distinct Chinese variants: Simplified, Traditional, and Hong Kong Chinese. This granular linguistic distinction serves as a direct indicator, pointing to a Chinese-speaking developer behind the operation.
Further evidence of a single operator controlling the entire campaign comes from the discovery of three shared Meta Pixel IDs across all 300 phishing domains, suggesting the use of Facebook advertisements to drive targeted traffic to these fraudulent pages.
Infostealer Threat and Protective Steps
Beyond the direct phishing efforts, an equally grave threat emerges from the infostealer pipeline. Malware such as Vidar and Lumma is distributed through lures like cracked software, malicious advertising networks, and illicit Telegram channels. These stealers are designed to extract all browser-stored credentials, session tokens, and cryptocurrency wallet seeds from infected devices. FIFA credentials are often collected as collateral damage, subsequently fueling account takeover attempts and resale on dark web markets.
What You Should Do
- For Organizations: Deploy Digital Risk Protection solutions for continuous monitoring and automated takedown of brand-impersonating infrastructure.
- For Fans:
- Only purchase tickets and merchandise through official FIFA channels.
- Enable multi-factor authentication (MFA) on all your online accounts, especially those related to FIFA or ticketing platforms.
- Be extremely cautious of FIFA-themed advertisements or messages, particularly those offering unusually low prices or employing countdown pressure tactics.
- Verify the URL of any FIFA-related website you visit. Look for “https://” and valid security certificates.
- Avoid clicking on suspicious links in emails, SMS messages, or social media posts related to the World Cup.
- For Financial Institutions: Implement alerts for transactions routed through the five identified payment channels associated with this campaign.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Tawk.to Live-Chat Property ID | mpnmccbabann9eohpoaomimm | GHOST STADIUM phishing kit backend tracker |
| Meta Pixel ID | 1912432924230210 | Shared Meta Pixel across GHOST STADIUM phishing domains |
| Meta Pixel ID | 2103242506309126 | Shared Meta Pixel across GHOST STADIUM phishing domains |
| Meta Pixel ID | 3156091303316034 | Shared Meta Pixel across GHOST STADIUM phishing domains |
| Cloned FIFA SSO Client ID | 74f02607-fc20-3132-a3650-1b93080bbn96f | Legitimate FIFA PingIdentity client_id used in phishing kit |
| Crypto Gateway | ChainUGO (testnet.chainugo.com) | Crypto on-ramp payment processor used by GHOST STADIUM |
| Adjacent Backend Domain | www[.]fifa[.]show | Backend domain tied to GHOST STADIUM phishing cluster |
| Facebook Ad ID | 1063360394213924210520024 | Facebook ad account tied to GHOST STADIUM campaign |
| Redirector Domain | football-ticket[.]top | Fraud-as-a-Service redirector domain (Origin IP: 34.97.164[.]110, registered April 26, 2026) |
| Redirector Domain | football-ticket[.]shop | Fraud-as-a-Service redirector domain (shared origin IP) |
| Redirector Domain | football-game[.]shop | Fraud-as-a-Service redirector domain (shared origin IP) |
| Redirector Domain | football-tickets[.]top | Fraud-as-a-Service redirector domain (shared origin IP) |
| Fraudulent Domain (sample) | fifa[.]bio | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fifa[.]center | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | goldfifa[.]red | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | salefifa[.]shopping | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fifa[.]show | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | skififa[.]black | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fifa[.]cafe | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fundfifa[.]market | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fifa[.]tax | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fifacash[.]city | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | fifahouse[.]com | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | www-fifa[.]com | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | www-fifa[.]shop | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | www-fifa[.]website | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | www-fifa[.]store | GHOST STADIUM core phishing domain |
| Fraudulent Domain (sample) | www-fifa[.]top | GHOST STADIUM core phishing domain |
| Hosting IP (Multi-Rail Fake Tickets) | 183.164.164[.]110 | IP hosting GHOST STADIUM multi-rail fake ticket domains |
| Hosting IP | 202.46.55.1[.]1 | IP tied to GHOST STADIUM phishing infrastructure |
| Hosting IP | 9355.112.212[.]251 | IP tied to GHOST STADIUM phishing infrastructure |
| Third-party Payment Gateway | pay[.]zfxupi[.]net | Redirects victims to Cash App and Chime for payments |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.