Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ghost stadium

Also known as: tracked as, YoroTrooper, Mustang Panda, T-APT-04, RattleSnake, Voldemort, reportedly sent around 20, they used Voldemort distri, AMOS, CVE-2022-0543, amvinfe at SuspectFile, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, SnappyClient, Bronze President, Lynx, India, SideWinder, Rattlesnake, APT-C-17

Description

Researchers uncovered a massive fraud ecosystem targeting the 2026 FIFA World Cup, identifying over 4,300 fraudulent domains impersonating FIFA's official website since August 2025. At the center operates GHOST STADIUM, a Chinese-speaking threat actor running a sophisticated phishing campaign across 300+ domains using a pixel-perfect clone of FIFA's authentication system. The operation harvests credentials, sells fake tickets, and processes payments through five distinct channels including cryptocurrency. Estimated losses from premium ticket fraud alone range from $71 million to $474 million, with total campaign losses potentially reaching billions. Six distinct fraud schemes operate in parallel: credential phishing, fake ticket sales, counterfeit merchandise, fake streaming platforms, fraudulent betting sites, and infostealer-driven credential theft. Over 2,513 FIFA account credentials are already circulating on dark-web markets. The campaign exploits Facebook advertising as its primary distribution chann...

Goals & Targeting

Targeted Sectors

Information technology
Entertainment
Financial services
Government
Defense
Healthcare
Media
Telecommunications
Aviation
Manufacturing
Hospitality
Maritime
Retail
Gaming
Critical infrastructure
Education
Transportation
Energy
Nuclear

Targeted Countries / Regions

United States of America
Argentina
Brazil
Canada
Colombia
Mexico
US
CN
MX
IN
UA
SG
EG
RU
BR
AU
VN
PK
CA
FR
IT
RO
NL
SA
JP
IL
IR
GB

AI Analysis

No AI analysis yet.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 14 IPv4 Address 1 Filename 1 SHA-256 Hash 4

References

  1. www.group-ib.com — Cited by web research for: YoroTrooper
  2. main.whoisxmlapi.com — Cited by web research for: Mustang Panda
  3. thisweekin4n6.com — Cited by web research for: amvinfe at SuspectFile
  4. www.group-ib.com — Cited by web research for: Telegram
  5. securityarsenal.com — Cited by web research for: CVE-2026-48558

Intel Summary

0

Techniques

44

Tools

7

Campaigns

74

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Phishing
Data Exfiltration

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
C
Confidence
55%
Added
May 27, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.