SOCRadar Uncovers Formula 1 Phishing Campaign

The SOCRadar Threat Research Unit (STRU) has identified and analyzed a multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets.

The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. The operation allows attackers to engage in real-time, operator-controlled social engineering, adapting their tactics to bypass multi-factor authentication (MFA) measures.

What sets this attack apart is the backend: Human operators watch each victim’s session live and push a bank specific verification screen tailored to the card just entered, adapting on the fly to get past MFA.

What SOCRadar Uncovered:

  • Full source code recovery: A hosting misconfiguration on one domain, f1-tickets-sg[.]com, let us pull the kit’s complete backend code rather than just the rendered pages – including the Python cloning script, which has Russian-language comments.
  • A 134-page storefront: The mirror reproduces the legitimate site’s entire information architecture (news, event info, FAQs, even the real 15-page Terms & Conditions PDF) far beyond what a stripped-down lure would need.
  • Bank specific fraud, chosen live: The kit reads the victim’s card BIN, identifies the issuing bank, and serves one of eight pre-branded challenge pages (Emirates NBD, RAKBank, HSBC, and five other mostly UAE institutions) while an operator on a live polling connection decides in real time whether to show an OTP prompt, a balance check, a push approval screen, or a generic fallback.
  • A wider domain network: At least 11 lookalike domains impersonate the Singapore and Spanish Grand Prix under a predictable naming pattern, sharing one backend; several are already flagged as malicious.

Why it matters: It is a manned fraud operation. A person is actively steering each victim toward the exact verification screen their bank would show, which is exactly what static phishing detection misses. It’s also a preview of how ticket phishing for major sporting events keeps evolving around those brief, high urgency sales windows.
IOCs include the domain cluster, the live C2 host at 144.31.3[.]209, and behavioral fingerprints such as the session cookie and the URL flags used to switch challenge screens.

To view the full research, please see SOCRadar Formula 1 Phishing Campaign

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading