WhoisXML API uncovered 62,081 domains referencing the 2026 U.S. midterm elections, including look-alike candidate stores traced to a few registrants. Download the threat research materials now.
Continue readingGHOST STADIUM Takes Advantage of FIFA 2026: DNS Deep Dive
Group-IB uncovered1 GHOST STADIUM, a Chinese-speaking, financially motivated threat actor running a sophisticated phishing campaign across more than 300 domains ahead of the 2026 FIFA World Cup. The operation deployed a near pixel-perfect clone of the official FIFA website, complete with a replicated single sign-on (SSO) authentication flow and multilanguage support, to harvest credentials and payment details from fans seeking tickets. Researchers estimated potential losses from premium ticket fraud alone at US$71–474 million.
Group-IB's investigation identified 48 network IoCs comprising domains and IP addresses. Aided by the WhoisXML API MCP Server2, we filtered out the domain IoCs our tools flagged as likely legitimate or inactive, narrowing our analysis to 47 IoCs.
Our DNS deep dive led to these discoveries:
- 14 of the domain IoCs that appeared in seven typosquatting groups with 3–8 members each
- Three of the domain IoCs that were likely registered with malicious intent
- 607 unique IP addresses that could belong to victims that communicated with 13 of the IP IoCs
- 3,083 email-connected domains, one of which was confirmed malicious
- 36 additional IP addresses, all of which were confirmed malicious
- 15 IP-connected domains
- 544 string-connected domains
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://www.group-ib.com/blog/ghost-stadium-football-fraud/
- [2] https://main.whoisxmlapi.com/ai/mcp-server