Fake CAPTCHA scam turns a quick click into a costly phone bill
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。好的,我先仔细看看文章内容。 文章主要讲的是一个利用虚假CAPTCHA页面进行诈骗的活动。骗子通过诱导用户点击,让用户在不知情的情况下发送大量国际短信,从而产生高额费用。这种方法不依赖于安装恶意软件,而是利用电信计费和联盟网络的漏洞来获利。 用户可能需要的是一个简洁明了的总结,重点突出诈骗手段、影响以及防范措施。考虑到字数限制,我需要抓住关键点:虚假CAPTCHA、发送国际短信、高额费用、影响用户和电信公司、防范建议。 然后,我得把这些信息浓缩成大约100字左右。可能的结构是:诈骗方式、受害者情况、后果以及如何防范。这样既全面又简洁。 最后,检查一下有没有遗漏的重要信息,比如涉及的国家和地区,以及具体的防范措施建议。确保总结准确传达文章的核心内容。 </think> 研究人员发现一种利用虚假CAPTCHA页面诱导移动用户在后台发送大量国际短信的诈骗活动。受害者点击后会被引导至伪装成简单图片选择或问答的页面,随后被迫发送包含多个国际号码的短信。这种诈骗利用国际短信高昂的终止费和收入分成协议获利,受害者可能面临高额费用,而电信运营商也可能蒙受损失。 2026-4-28 10:46:1 Author: securityboulevard.com(查看原文) 阅读量:2 收藏

The post Fake CAPTCHA scam turns a quick click into a costly phone bill appeared first on Malwarebytes.

Researchers have documented a long‑running campaign that uses fake CAPTCHA pages to trick mobile users into sending dozens of international SMS messages in the background.

If you’ve spent any time on today’s web, CAPTCHAs may seem like background noise: click a few traffic lights, prove you’re human, move on. Something scammers have learned to abuse in ClickFix campaigns where they lure victims into infecting their own machines.

Recently, though, researchers found a twist where “prove you’re human” quietly turns into “run up an international phone bill.” The research describes an International Revenue Share Fraud (IRSF) campaign. IRSF, also known as SMS pumping fraud, abuses the complex pricing structures of international calls and SMS traffic to generate revenue by inflating message volume to particular destinations.

Instead of installing malware on the victim’s device, the scam exploits how telecom billing and affiliate networks work, turning ordinary web traffic into premium SMS revenue for cybercriminals.

How it works

A typical flow for the scam looks like this:

  • Victims arrive via malvertising or TDS redirects, often from typosquatted telecom domains, onto a page that looks like a basic image‑selection or quiz CAPTCHA.
  • To “continue,” they’re prompted to tap a button that opens their SMS app with a prefilled message and recipient list.
  • This isn’t one SMS to one number. The fake CAPTCHA runs through multiple steps, and each message is preconfigured with more than a dozen international numbers across 17 countries known for high termination fees, including Azerbaijan, Myanmar, and Egypt.

On a typical consumer plan, that can translate to roughly $30 in international SMS charges per person, with a slice of the termination fees flowing back to the attacker via revenue‑sharing agreements.

To keep you from simply backing out, the pages deploy dedicated back‑button hijacking. JavaScript rewrites browser history and bounces you back to the scam when you try to leave.  The researchers also found the campaign was plugged into a Click2SMS‑style affiliate network that advertises “all kinds of traffic allowed” and carrier billing, effectively packaging IRSF as another monetization option for shady publishers.

This operation defrauds both individuals and telecom carriers. Victims face unexpected premium SMS charges on their bills and may struggle to trace the cause. Carriers pay revenue shares to the perpetrators and may absorb losses from customer disputes or chargebacks.


Mobile protection, anywhere, anytime.


How to protect yourself

Never send an SMS to “prove you’re human.” Legitimate CAPTCHAs run entirely in your browser. They won’t open your SMS or dialer app.

Check your mobile bill regularly for small, unfamiliar international SMS charges, not just big spikes. If you see anything suspicious, dispute it quickly and ask your provider to block international or premium SMS if you don’t need it.

Use a mobile protection app that blocks known malicious sites, like these domains involved in this campaign:

  • sweeffg[.]online
  • colnsdital[.]com
  • zawsterris[.]com
  • megaplaylive[.]com
  • ruelomamuy[.]com
Malwarebytes blocks ruelomamuy[.]com
Malwarebytes blocks ruelomamuy[.]com

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

*** This is a Security Bloggers Network syndicated blog from Malwarebytes authored by Malwarebytes. Read the original post at: https://www.malwarebytes.com/blog/news/2026/04/fake-captcha-scam-turns-a-quick-click-into-a-costly-phone-bill


文章来源: https://securityboulevard.com/2026/04/fake-captcha-scam-turns-a-quick-click-into-a-costly-phone-bill/
如有侵权请联系:admin#unsafe.sh