PULSE NAME
The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament
WHITE GHOST STADIUM AlienVault 2026-05-27 Modified: 2026-05-27
60
IOCs
HIGH VOLUME
Researchers uncovered a massive fraud ecosystem targeting the 2026 FIFA World Cup, identifying over 4,300 fraudulent domains impersonating FIFA's official website since August 2025. At the center operates GHOST STADIUM, a Chinese-speaking threat actor running a sophisticated phishing campaign across 300+ domains using a pixel-perfect clone of FIFA's authentication system. The operation harvests credentials, sells fake tickets, and processes payments through five distinct channels including cryptocurrency. Estimated losses from premium ticket fraud alone range from $71 million to $474 million, with total campaign losses potentially reaching billions. Six distinct fraud schemes operate in parallel: credential phishing, fake ticket sales, counterfeit merchandise, fake streaming platforms, fraudulent betting sites, and infostealer-driven credential theft. Over 2,513 FIFA account credentials are already circulating on dark-web markets. The campaign exploits Facebook advertising as its primary distribution chann...
Indicators of Compromise (4 / 60 total)
All FileHash-SHA1 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://fifa-tickets.vip/authorize.html 2026-05-27
URL http://fifa-tickets.vip/pay/FWC20260418A3230F12AC 2026-05-27
URL http://fifa-tickets.vip/tickets_shop 2026-05-27
URL http://www.billplz.com/bills/6e88393d1b82ede9 2026-05-27