Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs
ID: 3c7b1c7e-f4c1-595b-bf96-2d6ae3a52546
STIX ID: report--3c7b1c7e-f4c1-595b-bf96-2d6ae3a52546
Feed Name: Infoblox Blog
Infoblox Threat Intel documents a long-running IRSF campaign that leverages TDS-driven fake CAPTCHA pages to coerce users into sending multiple international SMS messages to premium/termination-fee numbers, generating revenue for the operators; the report details the redirection chains, JavaScript-based SMS launching, back-button hijacking, cookie/tracking mechanisms, phone-number lists (spanning 17 countries), hosting/DNS patterns (notably AS15699/Adam EcoTech), and provides a curated list of indicators for detection and mitigation — key takeaway: do not send SMS to confirm you are human.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
