Valid Points · June 2026
Massive World Cup Phishing Campaign, Bulk Enrichment, and More
Expanding GHOST STADIUM's World Cup phishing infrastructure to 6,113 domains, plus daily collection for six more DNS record types and a new bulk search.
Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. This month we analyzed domains used with a phishing kit targeting World Cup fans and ticket buyers, enabled daily collection for TXT, MX, SRV, HTTPS, CAA, and SOA record types and much more. As always, we appreciate any feedback!
The Validin Team
FEATURED RESEARCH
⚽️ Offside and Online: GHOST STADIUM Phishing Targeting World Cup Fans
Building on Group-IB's original report, Validin expanded GHOST STADIUM's known infrastructure using YARA-based response-body hunting, path pivots, and lookalike-domain enumeration. We identified 6,113 suspected FIFA-themed domains, of which 3,079 are still active with many Cloudflare-fronted. We share the full indicator list, along with helpful pivots.
BY THE NUMBERS
Top-viewed threat actor profiles and how their ranking changed from last month. If you're logged into Validin, you can view the full profiles:
PLATFORM UPDATES
💬 Data Collection Upgrades & New Bulk Search
In June alone, we rolled out significant improvements to our data collection pipeline, now catching very short-lived infrastructure and moving to daily scans of TXT, MX, SRV, HTTPS, CAA, and SOA records. We launched an improved bulk search experience to enrich up to 1,000 indicators at a time, and redesigned the Threat Profiles page to surface recently active threat groups and indicators added per day.

IN CASE YOU MISSED IT
👋 See you at LABScon
The Validin team is heading to LABScon this September and we'll be back as a strategic sponsor. See you all in Arizona this fall!
SPOT VALIDIN IN...
🧵 Pulling the Thread: Two Unreported Infrastructure Clusters Linked to Chinese Espionage Tooling
Researcher Plausible Deniability documented two previously unreported infrastructure clusters tied to Chinese state-sponsored espionage tooling, published early to maximize defensive value before the infrastructure rotates. The findings extend a known ShadowPad cluster through certificate and shared IP-block pivots, and a Winnti ELF C2 cluster through confirmed samples and Alibaba Cloud lookalike domains, with confidence levels flagged throughout and no group-level attribution claimed. Read the full analysis here.
Get in touch
Contact us
Validin is the first tab I open every morning.
