GHOST STADIUM
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor tracked by Group-IB as part of a broader Chinese-language phishing ecosystem targeting the 2026 FIFA World Cup. Group-IB reported the actor was first observed in November 2025 and identified it as one of four independent threat actors targeting the tournament. The actor operated a coordinated phishing and ticket-fraud campaign across more than 300 active domains, while the wider infrastructure included more than 4,000 fraudulent domains registered since August 2025, with thousands reportedly parked for later activation. According to the reporting, GHOST STADIUM used a custom React-based phishing kit built with the Layui 2.7.6/2.7.6m UI framework to create near pixel-perfect clones of FIFA ticketing and authentication pages. The kit replicated FIFA’s PingIdentity-based single sign-on flow using a real client_id from the legitimate service, harvested credentials and personal data including email addresses, physical addresses, and phone numbers, and in some cases abused password reset functionality to lock victims out of their FIFA accounts. The phishing workflow then redirected victims to the legitimate FIFA site to make the compromise appear successful. Distribution and victim acquisition relied on Facebook Ads as a primary channel, along with search engine poisoning, Google search results, Telegram, and WhatsApp. Group-IB linked campaign infrastructure through shared Meta Pixel IDs, shared SSL certificates, identical HTML content, and a shared Tawk.to property ID. The phishing pages supported 11 languages and distinguished among Simplified Chinese, Traditional Chinese, and Hong Kong Chinese; Group-IB also reported Chinese-language comments in the source code as an attribution signal. The campaign targeted football fans seeking FIFA World Cup tickets, especially premium and hospitality tickets, and also stole FIFA account credentials. Reporting cited at least 47,000 victims, theft of up to $10,000 per ticket, and more than 2,500 FIFA account credentials circulating on dark-web markets. Group-IB estimated losses ranging from tens or hundreds of millions of dollars for premium-ticket fraud alone, with broader campaign losses potentially reaching into the billions. Known alias in the provided content: Ghost Stadium.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Consumer Services
Where they target
Geographies tied to known operations.
- 🇬🇧 United Kingdom
- 🇵🇹 Portugal
- 🇪🇸 Spain
- 🇩🇿 Algeria
- 🇺🇸 United States
- 🇨🇦 Canada
- 🇲🇽 Mexico
- 🇧🇷 Brazil
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a large-scale FIFA-themed phishing and online fraud campaign, cloning hundreds of websites to conduct ticket fraud and related scams tied to the 2026 FIFA World Cup.
Chinese-language phishing-as-a-service operator conducting large-scale fraud against FIFA World Cup fans using cloned FIFA ticketing and SSO phishing sites, fraudulent domains, paid social media ads, search poisoning, and messaging-platform distribution to steal credentials, personal data, and funds.
Chinese-language phishing-as-a-service operator running a large-scale fraud campaign targeting FIFA World Cup fans with cloned ticketing and SSO phishing sites, stealing payment data and FIFA account credentials.
Financially motivated operator running a large-scale FIFA World Cup 2026 fraud campaign centered on credential phishing and fake ticket sales via 300+ domains impersonating FIFA, using cloned SSO flows, fake checkout pages, and multiple payment channels.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.