Ticket-Heist-Betrügerbande nutzt 700 Domains, um gefälschte Olympia-Tickets zu verkaufen

Teilen:

A large-scale fraud campaign with over 700 domain names is likely targeting Russian-speaking users looking to purchase tickets for the Summer Olympics in Paris.

The operation offers fake tickets to the Olympic Games and appears to take advantage of other major sports and music events.

Researchers analyzing the campaign are calling it Ticket Heist and found that some of the domains were created in 2022 and the threat actor kept registering an average of 20 new ones every month.

Overpriced fake Olympic Games tickets

In late 2023, researchers at threat intelligence company QuoIntelligence noticed increased conversation about the Olympic Games in Paris scheduled to start this July 26th.

Because the event has always been used for geopolitical influence and the International Olympic Committee’s decision to ban Russian and Belarusian athletes’ participation under their country flag, researchers kept monitoring the topic and looked for suspicious activity online.

QuoIntelligence kept an eye on specific keywords (e.g. ticket, Paris, discount, offer) used in newly registered domains and discovered operation Ticket Heist which relies on 708 domains hosting convincing websites claiming to sell valid tickets and provide accommodation options for the Olympic Games in Paris.

The first such domains discovered were ticket-paris24[.]com and tickets-paris24[.]com, the latter being a clone of the first.

“Despite minor spelling and grammar mistakes, likely due to direct translation from Russian to English, the website and its user experience were comparable to those of a high-end site” – QuoIntelligence

The user interaction that the Ticket Heist operators created for visitors appears legitimate and encourages engagement with the site and ticket selection.

Ticket Heist page for fake Olympic Games tickets
Ticket Heist page for fake Olympic Games tickets
source: QuoIntelligence

In a report today, the researchers say that the same UI framework is present across all websites related to Ticket Heist, with only minor variations in content and language making the difference between the fraudulent websites.

Apart from the design of the websites, what stands out in the scheme is the price of the fake tickets offered. QuoIntelligence notes that the prices are inflated compared to the legitimate ones.

“For example, a random event and seat location on the official website could cost less than EUR 100, whereas the same tickets and locations on the fraudulent websites were priced at a minimum of EUR 300, often reaching EUR 1,000” – QuoIntelligence

QuoIntelligence threat researcher Andrei Moldovan told BleepingComputer that while there is no confirmation, the higher prices could be part of a trick to make victims believe they get “premium treatment” for the extra money since the tickets are not available through the official distribution channels.

Alternatively, a higher price could also make victims believe that it’s a scalping operation that takes advantage of the shortage of tickets.

While trying to test their theories about the objective of Ticket Heist and to gather information that could lead to who is behind it, QuoIntelligence attempted a purchase from one of the fraudulent websites.

They found that all transactions are carried out through the Stripe payment processing platform and the money is transferred only when the card has sufficient funds.

This means that the operator’s goal is not to collect credit card information but to steal money from the victim.

Furthermore, this test also revealed the company name VIP Events Team LLC, which was created on November 26, 2021, and is still active but its website has never been indexed by public search engines.

“The domain was registered on the same day the company was formed. There are no mentions of VIP Events Team LLC on Google, social media, TrustPilot, or any other available OSINT sources” – QuoIntelligence

The researchers say that while the company appears to be based in New York, the “contact us” section on ticket-paris24[.]com lists the company behind it as located in Tbilisi, Georgia.

Analyzing the infrastructure behind the Ticket Heist operation, the researchers discovered that all the fraudulent domains were hosted at the same IP address, 179[.]43[.]166[.]54, belonging to a provider is linked to malicious activities by multiple services.

While every website has a unique SSL certificate, QuoIntelligence noticed a pattern in the structure of the domain and unique subdomain names used.

They observed that the subdomains often included jswidgetwidget-frame, or widget-api, which, combined with DNS records and common JavaScript files, helped them uncover the entire network of 708 domains.

Every month, the threat actor registered an average of 20 new domains but last November the number recorded a significant increase with 50 new domains being created.

Currently, 98% of the domains linked to Ticket Heist are considered clean of malware by crowdsourced analysis services, which supports the theory that the objective is to steal directly from victims through a legitimate payment service.

Event lures and victims

The Olympic events in Paris were not the only lures in operation Ticket Heist. The fraudsters also tried to lure victims with fake tickets for the UEFA European Championship this year.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:22 pm, Jan. 19, 2025
Wetter-Symbol 3°C
L: 1° | H: 3°
overcast clouds
Luftfeuchtigkeit: 86 %
Druck: 1020 mb
Wind: 3 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:55 am
Sonnenuntergang: 4:26 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
1° | 3°°C 0 mm 0% 6 mph 88 % 1019 mb 0 mm/h
Di. Jan. 21 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 4 mph 95 % 1017 mb 0 mm/h
Mi. Jan. 22 9:00 pm
Wetter-Symbol
4° | 6°°C 1 mm 100% 6 mph 99 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
4° | 8°°C 1 mm 100% 14 mph 89 % 1006 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
4° | 11°°C 1 mm 100% 25 mph 93 % 1007 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 86 % 1019 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 80 % 1019 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 1 mph 76 % 1019 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 72 % 1019 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 5 mph 70 % 1019 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 6 mph 76 % 1017 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 82 % 1018 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 88 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,719.09
-3.76%
Ethereum(ETH)
€3,095.35
-3.09%
XRP(XRP)
€2.89
-7.74%
Fesseln(USDT)
€0.97
-0.03%
Solana(SOL)
€238.46
-4.45%
Dogecoin(DOGE)
€0.347220
-9.29%
USDC(USDC)
€0.97
0.08%
Shiba Inu(SHIB)
€0.000019
-10.67%
Pepe(PEPE)
€0.000016
-12.44%
Peanut das Eichhörnchen(PNUT)
€0.425689
-14.43%
Nach oben scrollen