GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans With 300+ Fake Domains
ID: d4bf3b85-2cde-51fe-9a1d-088cb23a77be
STIX ID: report--d4bf3b85-2cde-51fe-9a1d-088cb23a77be
Feed Name: cybersecurityNews.com
Threat Score
Researchers uncovered a coordinated, high-scale fraud operation (GHOST STADIUM) exploiting FIFA World Cup 2026 ticket demand: a React-based phishing kit clones FIFA’s SSO (using a real client_id) across 300+ domains and 3,500+ impersonating sites, while Vidar and Lumma infostealers harvest browser credentials and session tokens; the report provides extensive IoCs (domains, IPs, Meta Pixel IDs, payment gateways) and recommends monitoring, takedown, MFA, and user caution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
