GHOST STADIUM is a financially motivated Chinese group using React-based phishing kits to steal SSO credentials by imitating FIFA.
Analyst brief
GHOST STADIUM is a Chinese-speaking, financially motivated threat group. It targets FIFA’s official website imitation using a custom React-based phishing kit that exploits the PingIdentity SSO login flow. The actor drives traffic via Facebook Ads across over 300 domains. Defenders should scrutinize FIFA-related SSO login pages, monitor traffic originating from Facebook Ads, and watch for credential leaks on dark-web markets.
GHOST STADIUM
unknown
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom React-based phishing kit that closely mimics FIFA's official website and exploits the PingIdentity SSO login flow. The campaign has the potential to generate financial losses estimated between $71 million and $474 million from premium ticket fraud alone, with total losses potentially reaching billions. GHOST STADIUM employs Facebook Ads as a primary traffic acquisition channel and has been linked to 2,513 compromised FIFA credentials available on dark-web markets. The actor is part of a broader fraud ecosystem that includes multiple parallel schemes, such as credential phishing and counterfeit merchandise sales.
What technology does the GHOST STADIUM group use to steal FIFA credentials?+
The group uses a custom React-based phishing kit that imitates FIFA's official website and targets the PingIdentity SSO login flow.
What measures should defenders take against the GHOST STADIUM phishing campaign?+
They should scrutinize FIFA-related SSO login pages, monitor traffic originating from Facebook Ads, and watch for credential leaks on dark-web markets.