logo

Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs

ID: a1f432a2-e89b-5f47-9ba6-baad32c94217

STIX ID: report--a1f432a2-e89b-5f47-9ba6-baad32c94217

Feed Name: Infoblox Threat Intel Blog

Threat Score
65/100

Date Published: 2026-04-23

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report documents an ongoing international fraud campaign (active since at least June 2020) that weaponizes fake CAPTCHA pages to coerce victims into sending multiple pre-populated international SMS messages (IRSF), leveraging Traffic Distribution Systems (TDS), affiliate tracking, and back-button hijacking to maximize scale and evade detection; the research includes technical flow details, cookie and DNS analysis, two tiers of phone-number lists across 17 countries, domain indicators, and reproducible fetch examples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.