Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs
ID: a1f432a2-e89b-5f47-9ba6-baad32c94217
STIX ID: report--a1f432a2-e89b-5f47-9ba6-baad32c94217
Feed Name: Infoblox Threat Intel Blog
This report documents an ongoing international fraud campaign (active since at least June 2020) that weaponizes fake CAPTCHA pages to coerce victims into sending multiple pre-populated international SMS messages (IRSF), leveraging Traffic Distribution Systems (TDS), affiliate tracking, and back-button hijacking to maximize scale and evade detection; the research includes technical flow details, cookie and DNS analysis, two tiers of phone-number lists across 17 countries, domain indicators, and reproducible fetch examples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
