PULSE NAME
Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs
WHITE AlienVault 2026-04-23 Modified: 2026-04-24
23
IOCs
MEDIUM VOLUME
Threat actors are leveraging fake CAPTCHA pages to trick victims into sending premium SMS messages as part of an international revenue share fraud (IRSF) scheme. Operating since at least June 2020, this campaign uses traffic distribution systems and social engineering to direct users through multi-stage fake verifications requiring SMS messages to international phone numbers across 17 countries with high termination fees. Each CAPTCHA step triggers messages to over a dozen destinations, generating over 60 SMS messages per victim costing approximately $30. The operation employs back button hijacking, sophisticated tracking cookies, and affiliate advertising networks to maximize reach while obscuring the fraud from detection. Both individual victims and telecommunication carriers suffer financial losses through this deceptive scheme.
Indicators of Compromise (23)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain 4lifetips.com 2026-04-23
domain caxip.com 2026-04-23
domain claimandwins.com 2026-04-23
domain mamil.com 2026-04-23
domain megaplaylive.com 2026-04-23
domain solpe.top 2026-04-23
domain vassin.top 2026-04-23
domain verifysuper.com 2026-04-23
domain zawsterris.com 2026-04-23
hostname chat.matchnewtoday.com 2026-04-23
hostname d.fufecarrol.top 2026-04-23
hostname d.herbosfinx.com 2026-04-23
hostname d.panzozerrot.com 2026-04-23
hostname d.remotesbuffalo.top 2026-04-23
hostname d.ruelomamuy.com 2026-04-23
hostname d.santafebuno.top 2026-04-23
hostname d.vistertransit.com 2026-04-23
hostname d.zerrotmamil.com 2026-04-23
hostname hotnow.sweeffg.online 2026-04-23
hostname r.buffalosolpe.top 2026-04-23
hostname r.carrolvassin.top 2026-04-23
hostname r.transitcaxip.com 2026-04-23
hostname vids.chatorizon.com 2026-04-23