Ghost Stadium is a Chinese-speaking, financially motivated phishing and online fraud operator focused on exploiting demand for the 2026 FIFA World Cup. The actor has been linked to a large cluster of fraudulent FIFA-themed infrastructure, including more than 300 active phishing domains within a broader ecosystem of thousands of lookalike registrations. Its operations center on fake ticketing, hospitality, and account-login workflows designed to steal payment data, personally identifiable information, and FIFA account credentials from fans seeking access to World Cup tickets. The actor is associated with a custom phishing kit that closely clones FIFA web properties and reproduces FIFA’s PingIdentity-based single sign-on flow. Reported functionality includes credential capture, password-reset abuse to lock victims out of legitimate accounts, and redirection back to the real FIFA site to reduce suspicion after compromise. The infrastructure has also been tied together through shared tracking and certificate artifacts, indicating centralized campaign management across many domains. Ghost Stadium distributes its lures primarily through paid social-media advertising, especially Facebook, with additional victim acquisition through search results and messaging platforms such as Telegram and WhatsApp. The campaign uses urgency and scarcity themes around premium and hospitality tickets, and supports multilingual targeting at scale. Reported monetization includes direct fraudulent ticket sales, harvesting of credentials for account takeover and ticket resale, and collection of payment and identity data. The actor has also been described as operating within a broader Chinese-language phishing-as-a-service ecosystem that lowers barriers for other criminals to run similar fraud campaigns. Known reporting consistently characterizes Ghost Stadium as a cybercriminal rather than state-sponsored actor. No verified sub-groups are established in the supplied facts beyond its identification as one of several independent threat actors exploiting the World Cup fraud ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese-speaking financial fraud cluster operating FIFA World Cup-themed phishing and impersonation infrastructure, including fraudulent domains and a phishing kit that mimics FIFA's PingIdentity-based single sign-on flow to harvest credentials and facilitate ticket fraud.
Financially motivated phishing and fraud operation using cloned FIFA ticketing/login sites to steal credentials, reset victim passwords, take over FIFA accounts, and resell tickets. The campaign is promoted via Facebook ads, Telegram, WhatsApp, and search results, and supports multiple payment methods including cryptocurrency.
Operates a large-scale FIFA-themed phishing and online fraud campaign, cloning hundreds of websites to conduct ticket fraud and related scams tied to the 2026 FIFA World Cup.
Chinese-language phishing-as-a-service operator conducting large-scale fraud against FIFA World Cup fans using cloned FIFA ticketing and SSO phishing sites, fraudulent domains, paid social media ads, search poisoning, and messaging-platform distribution to steal credentials, personal data, and funds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.