Pre-Registration Wave is a financially motivated fraud cluster associated with bulk registration of FIFA-themed domains in advance of the 2026 FIFA World Cup. It is characterized by large-scale domain squatting and pre-positioning of infrastructure used to support fan-targeted scams, including fake streaming services, counterfeit merchandise storefronts, and fraudulent betting platforms. The activity forms part of a broader World Cup fraud ecosystem in which thousands of impersonating domains were registered and a substantial subset was activated for monetization. This actor category is distinguished by preparatory infrastructure buildup rather than a single malware family or intrusion set. Its operations rely on brand impersonation, deceptive web properties, and traffic acquisition through common consumer-facing channels to lure victims seeking event-related services and products. The schemes are designed to monetize fan interest before and during the tournament through payment fraud, counterfeit sales, and other online deception. High-confidence reporting supports financial gain as the dominant motive. No specific country of origin, victim-country concentration, ransomware activity, or additional intrusion lifecycle capabilities are established at high confidence for this actor category beyond spoofing and initial access via fraudulent web lures.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.