Over 1,000 Fake IPL Domains Uncovered in Major Cyber Fraud Operation Targeting Fans

Published:

spot_img

Over 1,000 Fake IPL Domains Uncovered in Major Cyber Fraud Operation Targeting Fans

A significant cyber fraud operation has been unveiled, targeting fans of the Indian Premier League (IPL). This scheme has revealed how organized criminal networks are exploiting the high demand for match tickets and free streaming access through a multitude of fake booking portals and malicious websites.

Scope of the Fraudulent Operation

Recent investigations have identified over 600 fraudulent domains masquerading as IPL ticket booking platforms, alongside more than 400 counterfeit streaming websites. These findings suggest a highly organized operation, employing professional designs and tactics that closely mimic legitimate online services.

Imitation of Established Platforms

The fraudulent websites have been reported to imitate well-known ticketing platforms such as BookMyShow and District by Zomato. They featured convincing user interfaces, secure payment gateways, automated ticket generation systems, and fabricated customer reviews. Fans searching for match tickets or live streams were often directed to these sites via Google advertisements, Facebook posts, Telegram channels, and Instagram reels.

Search Engine Manipulation

Investigators found that these fraudulent domains utilized aggressive search engine optimization (SEO) techniques, allowing them to appear alongside legitimate platforms in search results. This manipulation significantly increased their visibility and likelihood of attracting unsuspecting users.

Deceptive User Experience

Once users accessed these sites, the experience was designed to appear genuine. Visitors could select seats, submit personal information, and complete payments via UPI or QR codes, ultimately receiving PDF tickets that contained fake booking references and non-functional QR codes. Many victims only realized they had been scammed upon arriving at stadiums, often just hours before a match when genuine tickets were no longer available.

Malware Distribution via Streaming Links

The investigation also uncovered that several fake streaming websites were being used to distribute malware. Users clicking on these streaming links could trigger redirects that deployed SHub Stealer, an infostealer designed to harvest sensitive information such as browser credentials, stored payment information, Apple Keychain data, and cryptocurrency wallet credentials from both Windows and macOS devices.

Advanced Targeting Techniques

Researchers highlighted advanced targeting methods for macOS users, where websites employed browser detection scripts to identify operating systems. Victims were redirected to fake Apple security update pages or GitHub installer links, often leading them to paste commands into Terminal, resulting in malware installation capable of extracting data for extended periods before detection.

Insights from the Administrative Panel

Investigators gained access to the administrative panel of one fraudulent ticketing operation, revealing backend systems designed to collect victim information, manage payments, and automate fraud processes. The operation was described as industrial-scale digital fraud, utilizing techniques typically found in legitimate e-commerce platforms.

Broader Cybercrime Context

The findings of this investigation emerged alongside other significant cybercrime activities, including claims by the Incransom ransomware group that it had breached Silergy Corp, stealing over 450GB of sensitive data. This overlap underscores how cybercriminal networks are simultaneously targeting both consumers and enterprises through multiple attack channels.

Recommendations for Users

The investigation concluded that while endpoint security tools can assist in detecting threats, user awareness remains critical. Researchers advised users to avoid purchasing tickets through social media links or search advertisements, instead accessing official websites directly through browsers and using only licensed streaming platforms. The report cautioned that similar fraud infrastructure is likely to resurface during future high-demand events.

For further reading, visit The Mainstream.

Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.

spot_img

Related articles

Recent articles

Dutch Police Investigate Vishing Call as Key Lead in Odido Cyberattack Exposing 6.39 Million Customers

Dutch Police Investigate Vishing Call as Key Lead in Odido Cyberattack Exposing 6.39 Million Customers The recent cyberattack on Odido, a major Dutch telecom provider,...

Cybersecurity Researchers Uncover “Ghostcommit”: A New Image-Based Attack Manipulating AI to Steal Sensitive Data

Cybersecurity Researchers Uncover "Ghostcommit": A New Image-Based Attack Manipulating AI to Steal Sensitive Data Cybersecurity researchers have identified a sophisticated supply chain attack technique dubbed...

Irvinder Singh Lail Appointed to Strengthen J.S. Held’s Global Capability Leadership

Irvinder Singh Lail Appointed to Strengthen J.S. Held's Global Capability Leadership In a significant move for the global consulting landscape, J.S. Held has appointed Irvinder...

From 17,000 to 1.1 Million Assets: Lumen Technologies Strengthens Exposure Management Through Comprehensive Data Reconciliation

From 17,000 to 1.1 Million Assets: Lumen Technologies Strengthens Exposure Management Through Comprehensive Data Reconciliation In a landscape where cybersecurity threats are increasingly sophisticated, accurate...