All Newsletters

Valid Points · June 2026

Massive World Cup Phishing Campaign, Bulk Enrichment, and More

Expanding GHOST STADIUM's World Cup phishing infrastructure to 6,113 domains, plus daily collection for six more DNS record types and a new bulk search.

Validin: VALID POINTS Newsletter

Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. This month we analyzed domains used with a phishing kit targeting World Cup fans and ticket buyers, enabled daily collection for TXT, MX, SRV, HTTPS, CAA, and SOA record types and much more. As always, we appreciate any feedback!

The Validin Team

Offside and Online: GHOST STADIUM Phishing Targeting World Cup Fans

FEATURED RESEARCH

⚽️ Offside and Online: GHOST STADIUM Phishing Targeting World Cup Fans

Building on Group-IB's original report, Validin expanded GHOST STADIUM's known infrastructure using YARA-based response-body hunting, path pivots, and lookalike-domain enumeration. We identified 6,113 suspected FIFA-themed domains, of which 3,079 are still active with many Cloudflare-fronted. We share the full indicator list, along with helpful pivots.

👉 Read the full write up here

BY THE NUMBERS

Top-viewed threat actor profiles and how their ranking changed from last month. If you're logged into Validin, you can view the full profiles:

  1. Kimsuky
  2. ClickFix
  3. Lazarus Group
  4. Fake Software Downloads
  5. FIN6 (new)

Data Collection Upgrades & New Bulk Search

PLATFORM UPDATES

💬 Data Collection Upgrades & New Bulk Search

In June alone, we rolled out significant improvements to our data collection pipeline, now catching very short-lived infrastructure and moving to daily scans of TXT, MX, SRV, HTTPS, CAA, and SOA records. We launched an improved bulk search experience to enrich up to 1,000 indicators at a time, and redesigned the Threat Profiles page to surface recently active threat groups and indicators added per day.

👉 Read the full product update blog here

Validin at LABScon

IN CASE YOU MISSED IT

👋 See you at LABScon

The Validin team is heading to LABScon this September and we'll be back as a strategic sponsor. See you all in Arizona this fall!

Learn more about LABScon 

SPOT VALIDIN IN...

🧵 Pulling the Thread: Two Unreported Infrastructure Clusters Linked to Chinese Espionage Tooling

Researcher Plausible Deniability documented two previously unreported infrastructure clusters tied to Chinese state-sponsored espionage tooling, published early to maximize defensive value before the infrastructure rotates. The findings extend a known ShadowPad cluster through certificate and shared IP-block pivots, and a Winnti ELF C2 cluster through confirmed samples and Alibaba Cloud lookalike domains, with confidence levels flagged throughout and no group-level attribution claimed. Read the full analysis here.

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company