Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flaws in Enterprise Java Platforms Let Attackers Execute Remote Code
August 7, 2026
Kimi K3 AI Model Sandbox Escape Exposes Sensitive Data
August 7, 2026
Critical npm Supply Chain Attack CHAINDROP Backdoors 400+ Packages
August 7, 2026
Home/Threats/GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans
Threats

GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans

Key Takeaways A sophisticated and financially motivated phishing campaign, dubbed “GHOST STADIUM,” is actively targeting FIFA World Cup fans. The operation leverages over 300 fake...

David kimber
David kimber
May 27, 2026 5 Min Read
82 0

Key Takeaways

  • A sophisticated and financially motivated phishing campaign, dubbed “GHOST STADIUM,” is actively targeting FIFA World Cup fans.
  • The operation leverages over 300 fake domains, impersonating official FIFA platforms to steal credentials, sell fake tickets, and distribute malware.
  • Multiple fraud schemes are running concurrently, making this a complex and pervasive threat.
  • Financial losses from this campaign could amount to billions of dollars, with thousands of legitimate FIFA account credentials already compromised.

Widespread Fraud Targets FIFA World Cup 2026 Fans with “GHOST STADIUM” Phishing

As anticipation builds for the 2026 FIFA World Cup, cybercriminals are unleashing a highly organized and expansive fraud operation designed to exploit the global fervor. Security researchers have identified a massive phishing campaign, codenamed “GHOST STADIUM,” which has deployed more than 300 fraudulent domains to ensnare unsuspecting football enthusiasts.

Table Of Content

  • Key Takeaways
  • Widespread Fraud Targets FIFA World Cup 2026 Fans with “GHOST STADIUM” Phishing
  • Exploiting Unprecedented Demand for Tickets
  • The GHOST STADIUM Threat Actor
  • GHOST STADIUM Phishing Campaign Mechanics
  • Infostealer Threat and Protective Steps
  • What You Should Do
  • Indicators of Compromise (IoCs):-

This meticulously crafted scheme is not only sophisticated but also exceptionally well-resourced, capable of deceiving even vigilant internet users. With the immense financial stakes surrounding the World Cup, this campaign represents one of the most significant cyber threats ever linked to a major sporting event.

Exploiting Unprecedented Demand for Tickets

The core of the “GHOST STADIUM” campaign capitalizes on the overwhelming demand for tickets to the FIFA World Cup 2026, which will be hosted across the United States, Canada, and Mexico. The initial two weeks of the ticket sales window saw over 150 million requests, creating a fertile ground for scammers to exploit the urgency and desperation of fans.

Fraudsters have established an extensive network of bogus websites, meticulously designed to mimic official FIFA platforms. Victims navigating to these sites often find it nearly impossible to distinguish them from legitimate sources, making them highly effective traps.

According to a report by Group-IB, shared with Cyber Security News (CSN), researchers have uncovered six distinct fraud methodologies, identified four independent threat actors, and pinpointed over 3,500 deceptive domains impersonating FIFA’s online presence.

The GHOST STADIUM Threat Actor

At the heart of this sprawling operation is a Chinese-speaking, financially driven threat actor known as GHOST STADIUM. This entity is orchestrating a coordinated phishing campaign across more than 300 domains, with potential financial losses from this single campaign estimated to reach into the billions.

The operation encompasses a diverse array of six parallel fraud schemes, each employing a different tactic to target football fans. These include:

  • Credential phishing to steal login information.
  • Fraudulent ticket sales.
  • Online storefronts selling counterfeit merchandise.
  • Deceptive streaming platforms.
  • Bogus betting websites.
  • Credential theft driven by infostealer malware.

Each of these schemes utilizes its own monetization strategy, complicating efforts to dismantle the entire operation through a singular takedown. Collectively, they form a rapidly expanding fraud ecosystem that is intensifying as the tournament draws nearer.

Already, over 2,513 confirmed FIFA account credential pairs are being traded on dark web markets, with prices ranging from $5 to $50 per pair. These credentials were not primarily acquired through targeted phishing but rather as incidental captures by broad infostealer campaigns, predominantly involving the Vidar and Lumma malware families.

Approximately 170,000 infostealer logs containing FIFA-related references have been identified, underscoring the vast scale of credential theft well in advance of the World Cup’s commencement.

GHOST STADIUM Phishing Campaign Mechanics

The GHOST STADIUM phishing kit is a custom-built, React-based single-page application that achieves an almost pixel-perfect replication of the official FIFA website. It is constructed using the Layui 2.7.6 framework, a Chinese UI library largely unknown outside of the Chinese developer community.

The kit faithfully mimics FIFA’s PingIdentity Single Sign-On (SSO) login process, leveraging a genuine client_id directly extracted from the actual FIFA SSO. Upon successful credential theft, the kit immediately initiates a password reset function to lock victims out of their accounts. Following this, it silently redirects them to the legitimate FIFA website, making the attack appear as a successful login attempt.

The phishing kit features automatic browser language detection, adapting its interface across 11 languages, including three distinct Chinese variants: Simplified, Traditional, and Hong Kong Chinese. This granular linguistic distinction serves as a direct indicator, pointing to a Chinese-speaking developer behind the operation.

Further evidence of a single operator controlling the entire campaign comes from the discovery of three shared Meta Pixel IDs across all 300 phishing domains, suggesting the use of Facebook advertisements to drive targeted traffic to these fraudulent pages.

Infostealer Threat and Protective Steps

Beyond the direct phishing efforts, an equally grave threat emerges from the infostealer pipeline. Malware such as Vidar and Lumma is distributed through lures like cracked software, malicious advertising networks, and illicit Telegram channels. These stealers are designed to extract all browser-stored credentials, session tokens, and cryptocurrency wallet seeds from infected devices. FIFA credentials are often collected as collateral damage, subsequently fueling account takeover attempts and resale on dark web markets.

What You Should Do

  • For Organizations: Deploy Digital Risk Protection solutions for continuous monitoring and automated takedown of brand-impersonating infrastructure.
  • For Fans:
    • Only purchase tickets and merchandise through official FIFA channels.
    • Enable multi-factor authentication (MFA) on all your online accounts, especially those related to FIFA or ticketing platforms.
    • Be extremely cautious of FIFA-themed advertisements or messages, particularly those offering unusually low prices or employing countdown pressure tactics.
    • Verify the URL of any FIFA-related website you visit. Look for “https://” and valid security certificates.
    • Avoid clicking on suspicious links in emails, SMS messages, or social media posts related to the World Cup.
  • For Financial Institutions: Implement alerts for transactions routed through the five identified payment channels associated with this campaign.

Indicators of Compromise (IoCs):-

Type Indicator Description
Tawk.to Live-Chat Property ID mpnmccbabann9eohpoaomimm GHOST STADIUM phishing kit backend tracker
Meta Pixel ID 1912432924230210 Shared Meta Pixel across GHOST STADIUM phishing domains
Meta Pixel ID 2103242506309126 Shared Meta Pixel across GHOST STADIUM phishing domains
Meta Pixel ID 3156091303316034 Shared Meta Pixel across GHOST STADIUM phishing domains
Cloned FIFA SSO Client ID 74f02607-fc20-3132-a3650-1b93080bbn96f Legitimate FIFA PingIdentity client_id used in phishing kit
Crypto Gateway ChainUGO (testnet.chainugo.com) Crypto on-ramp payment processor used by GHOST STADIUM
Adjacent Backend Domain www[.]fifa[.]show Backend domain tied to GHOST STADIUM phishing cluster
Facebook Ad ID 1063360394213924210520024 Facebook ad account tied to GHOST STADIUM campaign
Redirector Domain football-ticket[.]top Fraud-as-a-Service redirector domain (Origin IP: 34.97.164[.]110, registered April 26, 2026)
Redirector Domain football-ticket[.]shop Fraud-as-a-Service redirector domain (shared origin IP)
Redirector Domain football-game[.]shop Fraud-as-a-Service redirector domain (shared origin IP)
Redirector Domain football-tickets[.]top Fraud-as-a-Service redirector domain (shared origin IP)
Fraudulent Domain (sample) fifa[.]bio GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fifa[.]center GHOST STADIUM core phishing domain
Fraudulent Domain (sample) goldfifa[.]red GHOST STADIUM core phishing domain
Fraudulent Domain (sample) salefifa[.]shopping GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fifa[.]show GHOST STADIUM core phishing domain
Fraudulent Domain (sample) skififa[.]black GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fifa[.]cafe GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fundfifa[.]market GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fifa[.]tax GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fifacash[.]city GHOST STADIUM core phishing domain
Fraudulent Domain (sample) fifahouse[.]com GHOST STADIUM core phishing domain
Fraudulent Domain (sample) www-fifa[.]com GHOST STADIUM core phishing domain
Fraudulent Domain (sample) www-fifa[.]shop GHOST STADIUM core phishing domain
Fraudulent Domain (sample) www-fifa[.]website GHOST STADIUM core phishing domain
Fraudulent Domain (sample) www-fifa[.]store GHOST STADIUM core phishing domain
Fraudulent Domain (sample) www-fifa[.]top GHOST STADIUM core phishing domain
Hosting IP (Multi-Rail Fake Tickets) 183.164.164[.]110 IP hosting GHOST STADIUM multi-rail fake ticket domains
Hosting IP 202.46.55.1[.]1 IP tied to GHOST STADIUM phishing infrastructure
Hosting IP 9355.112.212[.]251 IP tied to GHOST STADIUM phishing infrastructure
Third-party Payment Gateway pay[.]zfxupi[.]net Redirects victims to Cash App and Chime for payments

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Tycoon 2FA AiTM Kit Bypasses MFA for Entra ID, Google Workspace

Next Post

Anthropic Updates Claude AI Code With Security Plugin

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Vanta Stealer Drains Browser, Crypto, and Gaming Accounts
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us