The 2026 FIFA World Cup is set to be the largest sporting event in history. Hosted across three nations — the United States, Canada, and Mexico — the tournament will take place from June 11 to July 19, 2026, featuring 104 matches played in 16 cities. The scale is unprecedented: FIFA estimates that more than six million fans will fill stadiums, with an average of 450,000 visitors per city. More than 150 million tickets were requested within the first 15 days of the sales window alone, making this edition approximately 30 times oversubscribed compared to previous tournaments. For context, the 2022 Qatar World Cup drew over 3.4 million in-stadium fans with an average attendance capacity of 96.3 per cent. The 2026 edition is expected to nearly double that figure.
This enormous demand — and the urgency it creates among fans desperate to secure tickets — has made the football tournament a magnet for fraud. Months before the opening whistle, Group-IB researchers have uncovered a sprawling ecosystem of fraud activity targeting the tournament and its global audience. The investigation identified more than 4,300 fraudulent domains impersonating FIFA’s official web presence registered since August 2025, six distinct fraud schemes running in parallel, four independent threat actors, and over 2,500 FIFA account credential pairs already circulating in dark-web markets.
At the centre of this ecosystem sits a threat actor Group-IB has designated GHOST STADIUM — a Chinese-speaking, financially motivated operator running a sophisticated phishing campaign across more than 300 domains. GHOST STADIUM has built a pixel-perfect clone of the official FIFA website, complete with a replicated single sign-on (SSO) authentication flow, and multi-language support in 11 languages. A conservative estimate based on the campaign’s observable infrastructure places the potential financial losses from premium ticket fraud alone (account for ~25% of 300+ phishing domains) at between $71 million and $474 million — and the total campaign losses across all tiers could reach into the billions.
![Figure 1: Example of a fraudulent domain fifa-tickets[.]vip/tickets_shop, tracked under the GHOST STADIUM phishing campaign.](https://www.group-ib.com/wp-content/uploads/figure-1-9.png)
Figure 1: Example of a fraudulent domain fifa-tickets[.]vip/tickets_shop, tracked under the GHOST STADIUM phishing campaign.
But GHOST STADIUM is not operating alone. Three additional threat actors — including a bulk domain squatter pre-positioning hundreds of typosquat domains, an industrialized infostealer ecosystem incidentally harvesting FIFA credentials at scale, and an underground supply chain of Phishing-as-a-Service (PhaaS) vendors lowering the barrier for new entrants — are exploiting the same event simultaneously. Together, they are running six parallel fraud schemes: credential phishing, fake ticket sales, counterfeit merchandise storefronts, fake streaming platforms, fraudulent betting and casino sites, and infostealer-driven credential theft.
This blog presents Group-IB’s research findings across the full fraud landscape, profiles the GHOST STADIUM threat actor, and introduces the Cyber Fraud Fusion (CFF) defence model — a coordinated framework that connects digital risk protection, threat intelligence, fraud prevention, cross-institutional intelligence sharing, and investigation services to predict and prevent fraud at the speed and scale of the campaign itself.
Group-IB customers can access our Threat Intelligence and Fraud Protection portals for more information about GHOST STADIUM, the wider fraud ecosystem targeting the FIFA World Cup 2026, and the full indicators of compromise identified in this research:


Figure 2: GHOST STADIUM phishing campaign attack chain and operational flow.
The GHOST STADIUM phishing kit is a custom React-based single-page application that clones the official fifa.com website to near pixel-perfect fidelity. The kit is built with the Layui 2.7.6 UI framework, a Chinese open-source library virtually unknown outside the Chinese developer community. FIFA’s legitimate single sign-on service is provided by PingIdentity, and the GHOST STADIUM phishing kit is even capable of replicating this using the actual client_id lifted from the real FIFA SSO.
The cloned flow is functionally indistinguishable from the legitimate login process as well including registration page and payment check out page. Critically, the phishing page scope parameters include p1:reset:userPassword, which authorises password reset — enabling the attacker to immediately lock legitimate users out of their accounts after capturing their credentials. The kit also requests email, address, and phone data, harvesting personal information beyond just login credentials. After capture, victims are silently redirected to the real https://www.fifa.com/auth, so the experience appears to be a successful login.
The phishing pages invest heavily in visual legitimacy. All product imagery and FIFA branding is loaded directly from FIFA’s official digital hub Content Delivery Network (CDN), making the page visually authentic at zero infrastructure cost while bypassing content-similarity detection tools that compare hash signatures of hosted images. The footer carries authentic links to FIFA’s real social media accounts and a Google Translate widget is embedded as an additional trust signal. This is not a crude phishing page — it is a meticulously engineered impersonation.
The kit auto-detects browser locale and switches its interface across 11 languages plus three Chinese variants (Simplified, Traditional, and Hong Kong). The supported languages include English, German, French, Spanish, Portuguese, Italian, Arabic, Japanese, Korean, Indonesian, and Russian. The granular enumeration of three Chinese locales goes beyond what is necessary for global reach and is itself an attribution signal — Chinese-speaking developers distinguish mainland, Taiwan, and Hong Kong locales because these are meaningful distinctions in their own linguistic environment.

Figure 3: Chinese-language comments in the source code, a key attribution evidence linking the GHOST STADIUM phishing kit to a Chinese-speaking developer.
Infrastructure analysis further confirms single-operator control. Shared SSL certificates and Meta (Facebook) Pixel IDs are embedded identically across 300+ phishing domains, tying all domains to the same Facebook advertising accounts. The byte-for-byte identical 415 KB HTML pages and same Tawk[.]to live-chat Property ID were detected used across 79 domains selling premium and hospitality tickets, confirming automated multi-domain provisioning from a single source kit.

Figure 4: Shared Meta Pixel code observed across multiple phishing domains attributed to GHOST STADIUM.

Figure 5: Group-IB Graph shows connected SSL certificates across the GHOST STADIUM campaign domains.

Figure 6: GHOST STADIUM victim journey.
The victim’s journey through the GHOST STADIUM campaign follows a carefully designed funnel. When a visitor arrives at any cluster domain, they are immediately presented with an aggressive fake popup mimicking official hospitality announcements, with a ‘BUY NOW’ call-to-action.
![Figure 7: Example of a fake “BUY NOW” pop-up on a fraudulent domain (www-fifa[.]com[.]co) replicating the exact layout and branding of the legitimate site hospitality promotion used to lure victims.](https://www.group-ib.com/wp-content/uploads/figure-7-3.png)
Figure 7: Example of a fake “BUY NOW” pop-up on a fraudulent domain (www-fifa[.]com[.]co) replicating the exact layout and branding of the legitimate site hospitality promotion used to lure victims.
![Figure 8: Example of a fraudulent ticketing page (www-fifa[.]com[.]co) that impersonates the official FIFA](https://www.group-ib.com/wp-content/uploads/figure-8-3.png)
Figure 8: Example of a fraudulent ticketing page (www-fifa[.]com[.]co) that impersonates the official FIFA “On Location” hospitality site.
The function is structured as a pseudo-legitimate purchase flow: match selection, bundle selection (premium tiers), seating tier selection, cart review, and checkout. Victims who click “Browse Tickets” are redirected through a match selection interface to a fake “Log In / Sign Up” page that harvests credentials. Any credential pair with a valid email pattern is accepted, after which the account takeover process is complete. If the victim has legitimate tickets associated with their FIFA account, the attacker can change their credentials, lock them out, and resell the tickets. New users seeking to purchase tickets are redirected to a buying form and then a fake checkout page that collects extensive personal information via POST: first name, last name, email address, phone number, street address, city, state/province, ZIP/postal code, country, and delivery instructions.

Figure 9: Example of a fake Log In / Sign Up page using the cloned PingIdentity SSO where credentials are captured.

Figure 10: Example of a fake checkout page collecting PII and payment details.
After clicking “Pay”, the attacker accepts payments through at least five distinct channels, demonstrating a level of operational sophistication designed to maximise conversion across different victim profiles and geographies:
FWC2026XXXXXXXXX, repeating across multiple domains and confirming a shared backend template.
Figure 11: Example of card checkout pages with shared Order # formatting across phishing domains.
pay[.]zfxupi[.]net, which offers Cash App and Chime as payment options. These gateways add a layer of perceived legitimacy and obscure the destination of funds.
Figure 12: Example of redirection to external payment gateways.

Figure 13: Examples of various peer-to-peer payment options.

Figure 13: Examples of various peer-to-peer payment options.

Figure 14: Example of geographic targeting with location-aware payment options.

Figure 15: Example of crypto on-ramp payment options.
Regardless of which payment channel is used, the result is the same: money flows to the attacker and the victim receives no tickets.
The observed fraud campaign targets the entire FIFA World Cup 2026 audience of over six million fans globally. Among the 300+ phishing sites, 79 were detected to provide only premium and hospitality tier tickets with pricing in the range of $1,500 to $10,000+. With more than 600 victims observed registering at a single domain, extrapolation across the 79 premium-focused sites suggests the victim count for premium and hospitality tier fraud alone may exceed 47,400 people, with financial losses ranging from approximately $71 million to $474 million USD.
These figures cover only the premium ticket fraud conducted by GHOST STADIUM. If one-quarter of the fake websites (79 out of 300+) can generate hundreds of millions of dollars in losses, the total profit from the entire campaign — including credential theft, lower-tier ticket fraud, and the broader ecosystem of downstream monetisation — could reasonably reach into the billions. Additionally, 2,513 confirmed FIFA credential pairs are already listed for sale in dark-web markets at $5 to $50 per pair, feeding a separate account-takeover pipeline that operates independently of the phishing infrastructure.
The GHOST STADIUM campaign uses multiple distribution channels to drive traffic to its phishing domains, with the exploitation of paid social media advertising serving as the primary acquisition engine.

Figure 16: Examples of scam ads abusing Facebook’s advertising platform with fake urgency pricing and countdown timer.
Telegram and WhatsApp: Beyond web-based phishing, the campaign pushes victims toward direct communication channels. Some scam pages and fake Facebook ads display “Call now” or “Message” buttons, or list phone numbers directly on their profiles. Telegram channels are also abused to distribute phishing links with limited-time offers. This multi-channel approach ensures that victims who do not click on web ads can still be reached through direct messaging.

Figure 17: Example of a “Call Now” button on scam social media pages that direct victims toward direct communication with the fraudsters.

Figure 18: Google search results showing fraudulent domains impersonating FIFA’s official web presence ranking alongside legitimate results.
football-ticket[.]top football-ticket[.]shop football-game[.]shop football-tickets[.]top
GHOST STADIUM does not operate in a vacuum. Investigations revealed a fourth threat actor category — Dark Web Fraud Kit Sellers (TA-4) — functioning as the supply-chain layer of the fraud ecosystem targeting the FIFA World Cup 2026. These underground vendors sell pre-built phishing kits , automated ticket-purchasing bots, domain inventories, and email phishing templates through dark-web forums. Their activity has been observed since mid-2025, well before the phishing campaigns began active deployment.
The existence of this supply chain has three critical implications. First, it lowers the barrier to entry: any aspiring fraud operator may purchase a ready-made kit and deploy it without the technical capability to build one from scratch. Second, it means that taking down one operator does not eliminate the threat — the same kit (or its variants) may be deployed by new entrants who purchase it from the underground market.
As the tournament approaches, this supply chain is expected to accelerate: more kits will appear, more operators will enter the market, and the fraud surface will expand. Disruption of the supply chain itself — targeting kit sellers, bot distributors, and credential brokers — is a necessary complement to individual campaign takedowns.
While the GHOST STADIUM credential phishing and fake ticket sales operation represents the highest-confidence and most technically detailed finding, it is only part of a broader fraud ecosystem exploiting the FIFA World Cup 2026. Four additional fraud schemes were identified operating in parallel, each with distinct monetisation mechanics and victim flows.
Fake streaming platforms: Approximately 55 domains were observed promising “free” or “premium” live streaming of World Cup matches. These sites target fans who cannot attend matches in person and are seeking online streaming options. Victims are required to register and pay a subscription fee; in return, they receive either no content or, in more sophisticated variants, browser-based stealers or Remote Access Trojans (RATs) that silently compromise the victim’s device. The dual monetisation model — subscription fees plus downstream credential theft from malware infections — makes these sites particularly damaging. Domain templates such as fifa2026tickets-streamlive[.]com and fifa-stream-* are common, often featuring countdown timers and fake “Malware Scanned” trust badges.
Counterfeit merchandise storefronts: Approximately 56 domains plus dedicated Telegram channels were detected selling fake FIFA, national team, and player-branded merchandise. These storefronts use product imagery lifted directly from legitimate sources and are localised in Spanish and Portuguese, indicating strong targeting of Latin American markets — particularly Brazil, Argentina, Mexico, and Colombia. Victims complete purchases by providing card details and shipping information (PII), then receive goods that are either counterfeit, materially inferior to what was advertised, or never shipped at all. The harvested PII, including card details, shipping addresses, and phone numbers, is sold downstream to carding marketplaces and scam-targeting databases.
Fraudulent betting and casino sites: Approximately 32 domains were identified operating unlicensed sportsbook and casino platforms that misuse FIFA branding to appear authorised. A notable sub-cluster uses Chinese-language interfaces to target Asian audiences. Victims who create accounts and make initial deposits find that winnings are never paid out and their deposits are stolen outright. More insidiously, these sites require KYC verification — passport scans, selfie photographs, and proof-of-address documents — which are then harvested and sold on dark-web markets for use in synthetic-identity fraud and fraudulent account opening at financial institutions.
Infostealer credential pipeline: The most pervasive but least targeted threat comes from mass infostealer campaigns, dominated by the Vidar and Lumma malware families. These infections are delivered through cracked-software lures, malvertising networks, Telegram cheat and mod channels. FIFA credentials are harvested as incidental collateral rather than as a targeted objective — the stealers copy all browser-stored credentials, cookies, autofill data, session tokens, and cryptocurrency wallet seeds from every infected device. Group-IB investigation identified approximately 130,000 infostealer logs containing FIFA references.
| Scheme | Direct Losses | Secondary Losses | Scale |
| Credential Phishing (Fake SSO) | FIFA account credentials; session cookies | Account takeover; unauthorised ticket transfers; identity theft; credential reuse | 300+ domains |
| Fake Ticket Sales | Crypto payment ($1,500–$10,000+ per ticket) | No chargeback; registration PII harvested | $71M–$474M estimated (premium tier, ~25% of campaign) |
| Fake Streaming | Subscription fees; card data | Malware infection; full browser-credential theft | ~55 domains |
| Counterfeit Merchandise | Card data; payment for counterfeit or undelivered goods | PII sold to carding markets and scam-targeting lists | ~56 domains + Telegram channels |
| Fraudulent Betting | Stolen deposits; winnings never paid | KYC documents (passport, selfie) sold for synthetic-identity fraud | ~32 domains |
| Infostealer Pipeline | Passwords, autofill, cookies, session tokens, crypto-wallet seeds | Corporate account pivot via SSO; MFA bypass via stolen session cookies | ~130,000 logs; 2,513 credential pairs |
Group-IB investigation identified four distinct threat actors operating across the fraud ecosystem targeting the FIFA World Cup 2026. These are not a single coordinated campaign but a convergence of independent operators exploiting the same high-profile event across different fraud vectors and platforms.
| Threat Actor | Type | Status | Scale | Primary Schemes |
| GHOST STADIUM (TA-1) | Phishing kit operator | Active | 300+ domains | Credential phishing; fake ticket sales |
| Pre-Registration Wave (TA-2) | Bulk domain squatter | Active | ~143 domains | Fake streaming; counterfeit merch; fraudulent betting |
| Infostealer Operators (TA-3) | Mass malware campaigns | Ongoing | ~130,000 logs | Credential theft (FIFA incidental) |
| Dark Web Kit Sellers (TA-4) | PhaaS vendor | Active from mid-2025 | Multiple forum listings | Supply chain — enables TA-1, TA-2, and new entrants |
The fraud ecosystem targeting the FIFA World Cup 2026 exposes a fundamental weakness in the way organisations currently defend against large-scale fraud campaigns: siloed response. When one phishing website is taken down, hundreds more remain operational and thousands are parked awaiting activation. When one bank flags a suspicious cryptocurrency address, other payment channels remain untouched and other financial institutions remain unaware. Sporting organization brand protection teams, the banks and crypto exchanges processing payments, the social media platforms distributing the ads, and law enforcement agencies all hold fragments of the picture — but no single institution holds the complete view. The result is that response happens domain by domain, institution by institution, always behind the attacker’s deployment pace.
This is the problem that Cyber Fraud Fusion (CFF) is designed to solve. CFF is a unified framework that coordinates five interdependent capabilities — Digital Risk Protection, Threat Intelligence, Fraud Protection, the Cyber Fraud Intelligence Platform, and Investigation Services — into a single defence architecture that operates at the speed and scale of the campaign itself. Applied to the GHOST STADIUM operation, CFF transforms the defence from a sequence of isolated reactions into a coordinated, predictive response.
The defence begins with the detection of a single GHOST STADIUM phishing domain. DRP’s continuous monitoring of social media, search engines, domain registrations, and web content identifies the fraudulent site through brand-impersonation signals. Graph analysis then expands this single detection into the full campaign infrastructure: one confirmed phishing domain reveals the 300+ connected domains through shared Meta Pixel IDs, the common Tawk.to Property ID, identical kit HTML fingerprints, and overlapping SSL certificates. DRP initiates automated takedown processes across the entire connected network while establishing ongoing monitoring of the approximately 3,800 parked domains for activation signals. Rather than playing whack-a-mole against individual domains, DRP maps and targets the infrastructure at the cluster level.
TI enriches DRP’s detection with deep infrastructure analysis. The team profiles the GHOST STADIUM phishing kit — the Layui framework, the cloned PingIdentity SSO, the Chinese-language source code artefacts — and maps the full operational footprint. TI monitors dark-web markets for the 2,513 compromised FIFA credential pairs, tracking their availability and identifying downstream buyers. The team analyses the threat actor’s TTPs, maps the five payment channels to their financial endpoints, and monitors the Phishing-as-a-Service supply chain for new kit variants or emerging operators. TI’s intelligence output feeds directly into Fraud Protection and CFIP for operational action.
The flagged indicators generated by DRP and enriched by TI are distributed to member institutions in real time through the Cyber Fraud Intelligence Platform (CFIP). Cryptocurrency wallet addresses associated with ChainUGO payment flows are shared with member exchanges, enabling deposits to threat-actor wallets to be frozen before funds are moved. Payment channel indicators — the specific cashtags, Nequi account numbers, FIXYD payment rails, and Alchemy Pay endpoints identified in the research — are distributed to the relevant payment providers and banks. FIFA’s account security team receives compromise signals for the 2,513 credential pairs identified in dark-web listings, enabling proactive account protection — forced password resets, session invalidation, and enhanced monitoring — before any buyer acts on the stolen credentials. CFIP’s strength is its reach: a detection at one institution becomes an alert at all participating institutions simultaneously, closing the gaps that the attacker exploits when institutions work in silos.
While DRP, TI, FP, and CFIP work to detect, prevent, and disrupt the campaign in real time, the Investigation team pursues the individuals behind GHOST STADIUM. The leaked ChainUGO API credentials, the Tawk.to operator account, the Meta Pixel advertising accounts, and the GNAME.COM registrar records all provide investigative starting points. Cryptocurrency tracing maps the flow of victim payments from ChainUGO through intermediary wallets to cash-out points at KYC-compliant exchanges, where account holder identities can be established. The evidence package — combining kit forensics, infrastructure mapping, financial flow analysis, and identity attribution — is built to a standard suitable for law enforcement referral and prosecution.
With CFF, a single phishing detection triggers a cascade: 300+ connected domains identified and targeted for takedown; 3,800 parked domains under monitoring; cryptocurrency wallets flagged across member exchanges; payment channels disrupted across five identified rails; 2,513 compromised accounts proactively secured; and the operator’s identity under active investigation. The campaign is disrupted at infrastructure, financial, and human levels simultaneously — not one domain at a time, but at the speed and scale of the campaign itself.
No single capability is sufficient against the scale of a fraud ecosystem such as the one targeting the FIFA World Cup 2026. DRP alone can take down domains, but cannot intercept payments or identify operators. TI alone can map infrastructure, but cannot freeze funds or alert financial institutions. FP alone can flag transactions, but cannot take down the phishing pages that drive them. Investigation alone can identify individuals, but cannot prevent losses in real time. It is only when these capabilities operate as a unified system — each team’s output feeding the next team’s input — that the defence matches the architecture of the attack. Four independent threat actors, six parallel fraud schemes, and over 4,300 domains demand a defence that is coordinated, predictive, and operates at ecosystem scale. That is what Cyber Fraud Fusion delivers.
The fraud ecosystem targeting the FIFA World Cup 2026 has already been fully operational months before the opening match. Four independent threat actors have deployed six distinct fraud schemes across more than 4,300 fraudulent domains impersonating FIFA’s official web presence, with GHOST STADIUM’s sophisticated phishing campaign at the centre. The scale of the infrastructure — 300+ active phishing domains, 3,800+ parked domains awaiting activation, 2,513 compromised credentials in dark-web circulation, and an underground supply chain feeding new operators into the ecosystem — means the threat will intensify as the tournament approaches and peak during the June 11 to July 19 match window.
The research demonstrates that this is not a problem that can be solved by any single institution working alone. Brand owners may struggle to take down every impersonated domain. Banks may not be able to freeze every payment channel. Law enforcement cannot investigate every operator. The speed, scale, and multi-channel nature of the campaign demand a coordinated response — a defence architecture that mirrors the scale and interconnection of the attack itself. The Cyber Fraud Fusion framework provides that architecture, connecting detection, intelligence, prevention, ecosystem-wide alerting, and investigation into a unified system that predicts and disrupts fraud before losses occur. The time to deploy that defence is now.
arrow_drop_down
The six parallel fraud schemes targeting football fans are:
arrow_drop_down
arrow_drop_down

Partial IOCs are listed in the blog; Group-IB customers can access the full list of IOCs from our complete Fraud Intelligence report.
IOC-1: GHOST STADIUM — Credential Phishing + Fake Ticket Sales (Crypto)
| Type | Value |
| Tawk.to live-chat property | 6976ccbaba77e8198a866266 |
| Meta Pixel #1 | 927432823410218 |
| Meta Pixel #2 | 1842358649811605 |
| Meta Pixel #3 | 1569148414168343 |
| Cloned FIFA SSO client_id | 35072598-fc20-4142-a469-1b940db47e6f |
| Crypto gateway | ChainUGO (testnet.chainugo.com) |
| Adjacent backend | www[.]fifa[.]show |
| Facebook Ad ID | 1874578493179313 |
| Facebook Ad ID | 1214564190491246 |
| Facebook Ad ID | 929714589420716 |
GHOST STADIUM Core Domains (representative sample of 79)
Hosting IPs (14 nodes)
IOC-2: Multi-Rail Fake Ticket Sales
| Type | Value |
| Chime cashtag | $Paramjit-Bains |
| Nequi account | 3202059757 |
| Regional rail domain | mm-fifa[.]top (FIXYD Mexico Payment) |
| Crypto on-ramp | Alchemy Pay |
| Redirector domain | football-ticket[.]top |
| Redirector domain | football-ticket[.]shop |
| Redirector domain | football-game[.]shop |
| Redirector domain | football-tickets[.]top |
| SSL fingerprint | 3b8bb7631b39f455d31544b55ba97b49ab1888c1 |
| SSL fingerprint | 84ecdca915f1af822ccc8a04479f5179104f353c |
| SSL fingerprint | 9bd164dd3f50d196c7dff4f6c1b0f1345ac96d9a |
IOC-3: Real Payment Gateway Redirect (160+ Domains)
| Type | Value |
| Entry domain | fifa-tickets[.]vip/tickets_shop |
| Login capture | fifa-tickets[.]vip/authorize[.]html |
| Payment order | fifa-tickets[.]vip/pay/FWC20260418A3230F12AC |
| Payment gateway abused | billplz[.]com |
| Example bill | www[.]billplz[.]com/bills/6e88393d1b82ede9 |
| URL parameter signature | ?aedda9bb-276d-49d4-92e8-294903503419/Design-ohne-Titel-1 |
Domain Naming Patterns to Avoid
Any domain matching these patterns and offering FIFA tickets, streaming, merchandise, or betting should be treated as potentially fraudulent:
Commonly abused TLDs: .com .online .shop .store .football .xyz .vip .top .icu .one .city .co .website .app
DISCLAIMERS:
The threat actor profile and attribution findings in this report are based on Group-IB technical analysis conducted between March 2026 to May 2026. All IOC data has been reviewed to protect the identities of victims; any remaining personal identifiers have been shared with law enforcement and are not reproduced here.
All technical information, including malware analysis, indicators of compromise and infrastructure details provided in this publication, is shared solely for defensive cybersecurity and research purposes. Group-IB does not endorse or permit any unauthorized or offensive use of the information contained herein. The data and conclusions represent Group-IB’s analytical assessment based on available evidence and are intended to help organizations detect, prevent, and respond to cyber threats.
Group-IB expressly disclaims liability for any misuse of the information provided. Organizations and readers are encouraged to apply this intelligence responsibly and in compliance with all applicable laws and regulations.
This blog may reference legitimate third-party services such as Facebook, Telegram and others, solely to illustrate cases where threat actors have abused or misused these platforms.
This material is provided for informational purposes, prepared by Group-IB as part of its own analytical investigation, and reflects recently identified threat activity.
All trademarks referenced herein are the property of their respective owners and are used solely for informational purposes, without any implication of affiliation or sponsorship.