Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site To Steal Fan Logins and Card Data
ID: d08c54fa-0a0d-5e28-a71d-54adc1edbe9e
STIX ID: report--d08c54fa-0a0d-5e28-a71d-54adc1edbe9e
Feed Name: Hunt.io Blog
This report documents a large, coordinated phishing campaign that clones FIFA's World Cup 2026 ticketing portal to steal login credentials and payment-card data. The operators re-host FIFA's React build under a /fifa/ path, add a Chinese Layui UI layer and operator scripts (common_main.js), embed Meta Pixels, and serve same-origin authentication and checkout flows on non-fifa hosts; these durable artifacts enable Hunt.io HuntSQL detection and pivoting (favicon, suspected origins 104.225.235.49 / 89.208.250.38 on AS25820/16clouds.com). The report provides detection rules, clustered IOCs (defanged), hosting and registrar patterns, and an attribution assessment recommending defenders hunt on structural markers rather than rotating domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
