International SMS Phishing Scams Exposed Through Fake CAPTCHA Pages
International Telecommunications Scam Uses Fake CAPTCHA Pages
Researchers have discovered a sophisticated scam that relies on fake CAPTCHA verification pages to trick users into sending expensive international text messages, generating significant illicit revenue for the attackers.
Sophisticated Scheme Utilizes Various Tactics
The scheme begins when users are redirected to a fake webpage through a commercial traffic distribution system. Upon arrival, they encounter a CAPTCHA that requests them to confirm their humanity by sending an SMS to a designated number. This seemingly innocuous action sets off a chain reaction, prompting further SMS messages to additional numbers chosen by the server.
Exploiting Delays in Billing Cycles
The scam takes advantage of the time delay between when the SMS is sent and when the corresponding charges appear on the victim’s bill, often several weeks apart. By the time the victim notices the charges, the scammer has already disappeared, leaving behind a trail of unsuspecting individuals who have unknowingly contributed to the scheme’s success.
Revenue Share Fraud and Premium-Rate Phone Numbers
An additional component of the scheme involves acquiring premium-rate phone numbers or number ranges and artificially inflating international calls or messages to these numbers. The holders of these numbers then reap revenue from termination charges obtained for inbound traffic, adding another layer of complexity to the scam.
Abuse of Traffic Distribution Systems
The attackers have also misused Keitaro TDS (Traffic Distribution System) to redirect visitors through complex redirection chains, evading detection and leveraging it as an all-in-one tool for traffic distribution, tracking, and cloaking. Over 120 distinct campaigns have employed Keitaro’s TDS for link delivery across a four-month period between October 2025 and January 2026.
Ai-Themed Investment Lures and Cryptocurrency Wallet-Drainers
The scam also incorporates AI-themed investment lures, utilizing deepfake videos and fake news articles to fabricate celebrity endorsements for cryptocurrency wallet-drainer schemes. Approximately 96% of Keitaro-linked spam traffic promoted such schemes, primarily through fake airdrops and giveaways centered on AURA, SOL, Phantom, and Jupiter cryptocurrencies.
Impact on Victims and Telecommunication Carriers
This operation defrauds both individual victims and telecommunication carriers, resulting in unexpected premium SMS charges for the former and revenue share payments to perpetrators along with potential losses from customer disputes or chargebacks for the latter.
