Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud
ID: 2ea7359e-1668-5552-89b1-2119f5376980
STIX ID: report--2ea7359e-1668-5552-89b1-2119f5376980
Feed Name: cybersecurityNews.com
Infoblox Threat Intel documented an ongoing International Revenue Share Fraud (IRSF) campaign that lures users to fake CAPTCHA pages via Traffic Distribution Systems (TDS). The pages prompt victims to send pre-filled international SMS messages to high-termination-fee numbers (e.g., Azerbaijan, Egypt, Myanmar), generating revenue for fraudsters and unexpected charges for users; the operation uses JavaScript preloaded numbers, back-button hijacking, and multi-stage redirects, has persisted since at least June 2020 across dozens of destinations, and is difficult for single providers to detect. Recommended actions include never sending SMS for CAPTCHAs, monthly bill checks, DNS/TDS blocking, and carrier-side real-time SMS monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
