Full Report
With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.
Analysis Summary
# Threat Actor: GHOST STADIUM
## Attribution & Identity
- **Name/Alias:** GHOST STADIUM
- **Origin/Language:** Chinese-speaking threat actor.
- **Identity:** Identified as one of four independent threat actors operating fraudulent schemes surrounding the 2026 FIFA World Cup.
## Activity Summary
- **Recent Campaigns:** A sophisticated phishing operation and massive fraud campaign targeting fans ahead of the 2026 FIFA World Cup.
- **Scale:** Part of a larger ecosystem involving over 4,300 fraudulent domains and six distinct fraud schemes.
- **Estimated Impact:** Researchers estimate potential financial losses could reach billions of dollars due to the sophistication and scale of the operation.
## Tactics, Techniques & Procedures
- **Domain Impersonation:** Registration of thousands of domains mimicking the official FIFA web presence and the official visa/ticketing portals.
- **Social Engineering:** Leveraging high-demand events (World Cup) to create urgency and trust.
- **Phishing Kits:** Deployment of sophisticated phishing pages designed to harvest credentials and financial information.
- **Payment Diversion:** Use of illegitimate payment gateways (e.g., abusing services like Billplz) to facilitate fraudulent transactions.
- **URL Parameter Signatures:** Use of unique identifiers/signatures in URLs to track victims or bypass simple filters.
## Targeting
- **Sectors:** Sports, Entertainment, Retail, Tourism, and Finance.
- **Geography:** Global (Any region where fans are attempting to access World Cup tickets, merchandise, or visas).
- **Victims:** Individual football fans, travelers, and visa applicants.
## Tools & Infrastructure
- **Infrastructure:** Over 4,300 fraudulent domains.
- **Defanged Domain Patterns:**
- `fifa-com[.]{TLD}`
- `www-fifa[.]{TLD}`
- `www-fifaworldcup[.]{TLD}`
- `vis-fifa[.]{TLD}` (Impersonating the official `vis.fifa.com`)
- `fifa2026tickets{city}[.]com`
- `www[.]billplz[.]com/bills/6e88393d1b82ede9` (Abused payment link)
- **Abused TLDs:** `.com`, `.online`, `.shop`, `.store`, `.football`, `.xyz`, `.vip`, `.top`, `.icu`, `.one`, `.city`, `.co`, `.website`, `.app`.
## Implications
GHOST STADIUM represents a significant financial threat to the global public. The actor's ability to scale infrastructure (thousands of domains) suggests a highly organized, well-funded operation. By impersonating critical infrastructure like visa and ticketing portals, they not only steal money but also harvest sensitive personal identifiable information (PII) that can be sold or used for secondary attacks.
## Mitigations
- **Domain Monitoring:** Implement Digital Risk Protection (DRP) to monitor for and take down look-alike domains matching the patterns identified above.
- **Public Awareness:** Organizations should educate users to only use the official `fifa.com` domain and verify SSL certificates.
- **Transactional Verification:** Financial institutions should flag and scrutinize transactions directed toward known fraudulent TLD patterns or suspicious third-party payment gateways associated with "FIFA" purchases.
- **Email Filtering:** Block emails containing the specific URL signature patterns and domain naming conventions identified in the report.