GHOST STADIUM Takes Advantage of FIFA 2026: DNS Deep Dive

Group-IB uncovered1 GHOST STADIUM, a Chinese-speaking, financially motivated threat actor running a sophisticated phishing campaign across more than 300 domains ahead of the 2026 FIFA World Cup. The operation deployed a near pixel-perfect clone of the official FIFA website, complete with a replicated single sign-on (SSO) authentication flow and multilanguage support, to harvest credentials and payment details from fans seeking tickets. Researchers estimated potential losses from premium ticket fraud alone at US$71–474 million.

Group-IB's investigation identified 48 network IoCs comprising domains and IP addresses. Aided by the WhoisXML API MCP Server2, we filtered out the domain IoCs our tools flagged as likely legitimate or inactive, narrowing our analysis to 47 IoCs.

Our DNS deep dive led to these discoveries:

  • 14 of the domain IoCs that appeared in seven typosquatting groups with 3–8 members each
  • Three of the domain IoCs that were likely registered with malicious intent
  • 607 unique IP addresses that could belong to victims that communicated with 13 of the IP IoCs
  • 3,083 email-connected domains, one of which was confirmed malicious
  • 36 additional IP addresses, all of which were confirmed malicious
  • 15 IP-connected domains
  • 544 string-connected domains

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.group-ib.com/blog/ghost-stadium-football-fraud/
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started