logo

Fake CAPTCHA Scam Abuses Verification Clicks to Send Costly International Texts

ID: fbba15ed-2fb6-578b-b5df-39eae6c447b4

STIX ID: report--fbba15ed-2fb6-578b-b5df-39eae6c447b4

Feed Name: HackRead

Threat Score
45/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Deeba Ahmed

...
...

Infoblox Threat Intelligence uncovered a long-running IRSF campaign (since at least June 2020) that redirects victims from typosquatted domains through traffic distribution systems to fake CAPTCHA pages which, via JavaScript, open the victim's SMS app with pre-filled premium-rate numbers. The scam leverages back-button hijacking to trap users, may cause dozens of high-cost international texts per session, and has been attributed to an affiliate of a European Click2SMS network operating on AS15699.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.