{"id":12541,"date":"2026-05-01T10:04:11","date_gmt":"2026-05-01T10:04:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/01\/new-fake-captcha-campaign-uses-sms-pumping-fraud-to-run-up-victims-phone-bills\/"},"modified":"2026-05-01T10:04:11","modified_gmt":"2026-05-01T10:04:11","slug":"new-fake-captcha-campaign-uses-sms-pumping-fraud-to-run-up-victims-phone-bills","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/01\/new-fake-captcha-campaign-uses-sms-pumping-fraud-to-run-up-victims-phone-bills\/","title":{"rendered":"New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims\u2019 Phone Bills"},"content":{"rendered":"<p>    New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims\u2019 Phone Bills<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly documented scam campaign is using fake CAPTCHA pages to silently trigger dozens of international SMS messages from victims\u2019 mobile phones, leaving them with unexpected charges on their phone bills. <\/p>\n<p>What looks like a routine \u201cprove you\u2019re human\u201d step online turns into a financial hit that many users never see coming.<\/p>\n<p>CAPTCHAs have become so common on websites that most people interact with them without a second thought. Clicking traffic lights, selecting crosswalks, or solving simple puzzles feels routine and harmless. <\/p>\n<p>Cybercriminals have learned to take advantage of this habit. This campaign follows the pattern of <a href=\"https:\/\/cybersecuritynews.com\/lumma-stealer-via-fake-cracked-software\/\" id=\"117411\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix-style attacks<\/a>, where users are tricked into taking actions that work against themselves, often without knowing what they just did.<\/p>\n<p>This particular operation runs what researchers describe as an International Revenue Share Fraud (IRSF) campaign, more commonly known as SMS pumping fraud. <\/p>\n<p>The scheme works by inflating the volume of SMS messages sent to specific international destinations that carry high termination fees. <\/p>\n<p>A portion of those fees then flows back to the attackers through revenue-sharing agreements built into the global telecom billing system. <\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2026\/04\/fake-captcha-scam-turns-a-quick-click-into-a-costly-phone-bill\" id=\"https:\/\/www.malwarebytes.com\/blog\/news\/2026\/04\/fake-captcha-scam-turns-a-quick-click-into-a-costly-phone-bill\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Malwarebytes analyst, Pieter Arntz identified this campaign<\/a>, noting that it is a long-running operation that targets everyday mobile users browsing the web.<\/p>\n<p>What makes this scam stand out is that it does not rely on malware or device compromise. No software gets installed on the victim\u2019s phone. <\/p>\n<p>Instead, the scam exploits how telecom billing systems and affiliate networks operate, quietly converting ordinary web traffic into premium SMS revenue for criminals. <\/p>\n<p>Each victim may not feel the hit immediately, but a single interaction can result in roughly $30 in international SMS charges on a standard consumer plan.<\/p>\n<h2 class=\"wp-block-heading\" id=\"inside-the-infection-mechanism\"><strong>Inside the Infection Mechanism<\/strong><\/h2>\n<p>Victims most often land on these fake CAPTCHA pages after being redirected through malvertising or Traffic Distribution System (TDS) redirects. <\/p>\n<p>Many of these redirects originate from typosquatted telecom domains, meaning web addresses that closely resemble legitimate telecom company websites. <\/p>\n<p>Once on the fake page, the user sees what appears to be a standard image-selection or quiz-style CAPTCHA.<\/p>\n<p>When the user taps the button to \u201ccontinue,\u201d their phone\u2019s native <a href=\"https:\/\/cybersecuritynews.com\/application-performance-monitoring-tools\/\" id=\"20055\" target=\"_blank\" rel=\"noreferrer noopener\">SMS application<\/a> opens with a message already pre-filled, along with a pre-loaded recipient list. This is where the real damage happens. <\/p>\n<p>The fake CAPTCHA takes the user through several steps, and each step sends a message to more than a dozen international numbers spanning 17 countries known for high SMS termination fees, including Azerbaijan, Myanmar, and Egypt.<\/p>\n<p>To prevent users from simply leaving the page, attackers use back-button hijacking. JavaScript on the <a href=\"https:\/\/cybersecuritynews.com\/is-zeely-a-scam-discover-the-pros-and-cons\/\" id=\"136341\" target=\"_blank\" rel=\"noreferrer noopener\">scam page<\/a> rewrites the browser\u2019s history so that pressing the back button just reloads the scam rather than taking the user away from it. <\/p>\n<p>This traps users in the flow long enough to complete multiple SMS sends. <\/p>\n<p>Researchers also found that this campaign connects to a Click2SMS-style affiliate network that openly advertises accepting \u201call kinds of traffic,\u201d essentially packaging IRSF as a revenue tool for shady web publishers.<\/p>\n<p>Users and organizations can take the following steps to reduce their risk from this type of fraud:-<\/p>\n<ul class=\"wp-block-list\">\n<li>Never send an SMS to verify your identity online. Legitimate CAPTCHA systems work entirely within the browser and will never open your SMS or phone dialer app.<\/li>\n<li>Review your mobile bill regularly for small, unfamiliar international SMS charges. Fraud like this often appears as minor charges that are easy to miss.<\/li>\n<li>If suspicious charges appear, dispute them with your carrier immediately and request that international or premium SMS be blocked on your account if you do not use those services.<\/li>\n<li>The following malicious domains are associated with this campaign and should be avoided: sweeffg[.]online, colnsdital[.]com, zawsterris[.]com, megaplaylive[.]com, and ruelomamuy[.]com.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-fake-captcha-campaign-uses-sms-pumping\/\">New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims\u2019 Phone Bills<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-fake-captcha-campaign-uses-sms-pumping\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims\u2019 Phone Bills A newly documented scam campaign is using fake CAPTCHA pages to silently trigger dozens of international SMS messages from victims\u2019 mobile phones, leaving them with unexpected charges on their phone bills. What looks like a routine \u201cprove you\u2019re human\u201d step online [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,649],"tags":[130],"class_list":["post-12541","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12541"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12541"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12541\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}