logo

Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site To Steal Fan Logins and Card Data

ID: d08c54fa-0a0d-5e28-a71d-54adc1edbe9e

STIX ID: report--d08c54fa-0a0d-5e28-a71d-54adc1edbe9e

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

This report documents a large, coordinated phishing campaign that clones FIFA's World Cup 2026 ticketing portal to steal login credentials and payment-card data. The operators re-host FIFA's React build under a /fifa/ path, add a Chinese Layui UI layer and operator scripts (common_main.js), embed Meta Pixels, and serve same-origin authentication and checkout flows on non-fifa hosts; these durable artifacts enable Hunt.io HuntSQL detection and pivoting (favicon, suspected origins 104.225.235.49 / 89.208.250.38 on AS25820/16clouds.com). The report provides detection rules, clustered IOCs (defanged), hosting and registrar patterns, and an attribution assessment recommending defenders hunt on structural markers rather than rotating domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.