New CAPTCHA Trap Uses SMS Pumping To Rack Up Massive Phone Charges

Cybercriminals have weaponized fake CAPTCHA pages in a sneaky international revenue share fraud (IRSF) campaign. This scam tricks mobile users into sending dozens of pricey international SMS messages without realizing it.

Unlike typical malware that infects devices, this attack exploits telecom billing quirks to generate cash for fraudsters. Researchers at Infoblox uncovered the long-running operation, which has racked up massive phone bills for victims worldwide.

CAPTCHA those “prove you’re human” tests with image selections or quizzes once felt harmless. Scammers, however, twist them into profit machines.

This campaign builds on tactics such as ClickFix malware, which causes users to download threats unwittingly.

How the Scam Unfolds

The attack kicks off with a realistic fake CAPTCHA page. It might ask you to select traffic lights or answer a quick quiz. A “Continue” button then pops open your phone’s SMS app, prefilled with a message and a list of international numbers.

This isn’t a single text. JavaScript on the page triggers multiple steps, each sending SMS to over a dozen high-fee numbers across 17 countries. Hotspots include Azerbaijan, Myanmar, and Egypt, where carriers charge steep per-message rates often $1–$3 each.

A full run? Easily 30+ messages, netting attackers around $30 per victim via revenue-sharing deals. They plug into Click2SMS-style affiliate programs that welcome “all traffic” and promote carrier billing as easy money for rogue publishers.

To trap you, pages hijack the back button. JavaScript manipulates browser history, looping you back to the scam if you try to escape. No malware installs; it’s all browser-based trickery abusing SMS permissions on Android and iOS.

Carriers indirectly foot much of the bill. They pay termination fees to fraudulent routes, then face customer disputes and chargebacks. Victims see surprise charges small at first, but they add up months later on statements.

Protecting Yourself from SMS Pumping Traps

Spot the red flags: Legit CAPTCHA never requests SMS or opens your messaging app. They run client-side in your browser using puzzles or behavioral analysis no phone involvement.

  • Scan bills monthly Hunt for tiny international SMS fees, not just huge jumps. Dispute them fast with your carrier.
  • Block premium traffic. Ask your provider to turn off international or premium SMS if unused many offer this for free.
  • Deploy mobile security. Apps like Malwarebytes block known bad domains and warn on malvertising. Enable Safe Browsing in Chrome or Safari.
  • Avoid shady links. Stick to HTTPS sites; use ad blockers to dodge TDS redirects. On Android, limit app SMS permissions.
  • Report fast. Forward suspicious texts to your carrier’s spam line (e.g., 7726 in the US) and flag domains on abuse reports.

Telecoms fight back with AI traffic monitoring, but user vigilance is key. This campaign shows IRSF evolving blending web scams with mobile billing exploits. Stay alert; one wrong tap could cost you dearly.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories