logo

Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs

ID: 3c7b1c7e-f4c1-595b-bf96-2d6ae3a52546

STIX ID: report--3c7b1c7e-f4c1-595b-bf96-2d6ae3a52546

Feed Name: Infoblox Blog

Threat Score
65/100

Date Published: 2026-04-23

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Infoblox Threat Intel documents a long-running IRSF campaign that leverages TDS-driven fake CAPTCHA pages to coerce users into sending multiple international SMS messages to premium/termination-fee numbers, generating revenue for the operators; the report details the redirection chains, JavaScript-based SMS launching, back-button hijacking, cookie/tracking mechanisms, phone-number lists (spanning 17 countries), hosting/DNS patterns (notably AS15699/Adam EcoTech), and provides a curated list of indicators for detection and mitigation — key takeaway: do not send SMS to confirm you are human.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.