The SOCRadar Threat Research Unit (STRU) has identified and analyzed a multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets.
The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. The operation allows attackers to engage in real-time, operator-controlled social engineering, adapting their tactics to bypass multi-factor authentication (MFA) measures.
What sets this attack apart is the backend: Human operators watch each victim’s session live and push a bank specific verification screen tailored to the card just entered, adapting on the fly to get past MFA.
What SOCRadar Uncovered:
- Full source code recovery: A hosting misconfiguration on one domain, f1-tickets-sg[.]com, let us pull the kit’s complete backend code rather than just the rendered pages – including the Python cloning script, which has Russian-language comments.
- A 134-page storefront: The mirror reproduces the legitimate site’s entire information architecture (news, event info, FAQs, even the real 15-page Terms & Conditions PDF) far beyond what a stripped-down lure would need.
- Bank specific fraud, chosen live: The kit reads the victim’s card BIN, identifies the issuing bank, and serves one of eight pre-branded challenge pages (Emirates NBD, RAKBank, HSBC, and five other mostly UAE institutions) while an operator on a live polling connection decides in real time whether to show an OTP prompt, a balance check, a push approval screen, or a generic fallback.
- A wider domain network: At least 11 lookalike domains impersonate the Singapore and Spanish Grand Prix under a predictable naming pattern, sharing one backend; several are already flagged as malicious.
Why it matters: It is a manned fraud operation. A person is actively steering each victim toward the exact verification screen their bank would show, which is exactly what static phishing detection misses. It’s also a preview of how ticket phishing for major sporting events keeps evolving around those brief, high urgency sales windows.
IOCs include the domain cluster, the live C2 host at 144.31.3[.]209, and behavioral fingerprints such as the session cookie and the URL flags used to switch challenge screens.
To view the full research, please see SOCRadar Formula 1 Phishing Campaign
Related
This entry was posted on August 5, 2026 at 12:54 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
SOCRadar Uncovers Formula 1 Phishing Campaign
The SOCRadar Threat Research Unit (STRU) has identified and analyzed a multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets.
The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. The operation allows attackers to engage in real-time, operator-controlled social engineering, adapting their tactics to bypass multi-factor authentication (MFA) measures.
What sets this attack apart is the backend: Human operators watch each victim’s session live and push a bank specific verification screen tailored to the card just entered, adapting on the fly to get past MFA.
What SOCRadar Uncovered:
Why it matters: It is a manned fraud operation. A person is actively steering each victim toward the exact verification screen their bank would show, which is exactly what static phishing detection misses. It’s also a preview of how ticket phishing for major sporting events keeps evolving around those brief, high urgency sales windows.
IOCs include the domain cluster, the live C2 host at 144.31.3[.]209, and behavioral fingerprints such as the session cookie and the URL flags used to switch challenge screens.
To view the full research, please see SOCRadar Formula 1 Phishing Campaign
Share this:
Like this:
Related
This entry was posted on August 5, 2026 at 12:54 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.