A new wave of malware infections has been attributed to an advanced infrastructure known as HelloTDS, which has leveraged FakeCaptcha as a central component in widespread campaigns.
Gen Threat Labs reports that this Traffic Direction System (TDS) has delivered millions of malware payloads to users worldwide, primarily through compromised streaming platforms, file-sharing domains, and malvertising channels.
The campaign has seen rapid proliferation, infecting over 4.3 million users in just April and May 2025, with the highest impact recorded in the United States, Brazil, India, parts of Western Europe, the Balkans, and several African nations.
Anatomy of the Attack
The HelloTDS infrastructure operates as an attacker-controlled decision engine embedded into legitimate-appearing websites, such as streaming services, torrent mirrors, and file-sharing platforms.

Upon visiting such a site, the victim’s browser retrieves a JavaScript loader from HelloTDS, which initiates an extensive fingerprinting process.
According to Gen Threat Labs Report, this process assesses the victim’s geolocation, IP reputation, device attributes, and browser characteristics specifically filtering out connections originating from VPNs or analysis environments.
If the fingerprinting routines determine a prospective victim, a follow-up script is delivered, capturing user interactions such as mouse movements and session behaviors.
This script ultimately triggers another request, leading to the final payload: a redirector that lands the user on one of several malicious destinations, notably FakeCaptcha pages, fake software updates, tech scams, or downloads laced with info-stealers like LummaC2.
Dynamic Domains
HelloTDS employs a constantly shifting array of domains often pseudo-English word combinations with top-level domains like .top, .shop, or .com registered mainly through Pananames in Panama, and served from IP ranges managed by SERVERS-COM (AS7979).
The attacker further obfuscates activity by rotating domains and DNS records, leveraging Let’s Encrypt certificates, and introducing unique HTTP headers (e.g., “megageocheckolololo”) in server responses.
The TDS infrastructure is adept at evading conventional detection techniques. It delivers benign content to known security research environments, forensic sandboxes, or users connecting via anonymizing proxies.
Conversely, real victims are served with malicious payloads including sophisticated FakeCaptcha prompts that exploit Unicode math characters to evade static analysis and heuristic detection.
FakeCaptcha, as deployed in these campaigns, impersonates legitimate CAPTCHA challenges but is designed to lure users into copying and executing malicious scripts often via the Windows Run dialog.

The malware delivered encompasses a broad array; from downloaders and remote access trojans to fake browser updates and fraudulent investment schemes, frequently targeting cryptocurrency wallets.
Interestingly, HelloTDS sometimes redirects non-targeted users to seemingly harmless investment platforms or browser extensions, ensuring a façade of legitimacy while monetizing benign traffic.
This duality helps the campaign maintain longevity and evade categorization as outright malvertising.
HelloTDS’s use of multi-stage fingerprinting, selective content delivery, and adaptive infrastructure highlights the need for layered defenses.
Security experts recommend deploying endpoint protection platforms, browser isolation, robust ad and script blockers, and routine monitoring for suspicious domain access patterns.
Users should exercise caution on file-sharing or streaming sites, and avoid executing commands from unfamiliar or suspect web prompts.
Understanding the structure and tactics of HelloTDS is critical to disrupting its chain of attack and minimizing FakeCaptcha’s impact on both enterprise and consumer networks.
Indicators of Compromise (IOCs)
| Category | Domain / IP / URL |
|---|---|
| Entry Websites | dailyuploads[.]net, streamtape[.]{to,net}, watchadsontape[.]com, bigwarp[.]art, savefiles[.]com |
| HelloTDS Domains | yr[.]unasonoric[.]com, gq[.]binesyorker[.]com, sb[.]rowlandpodogyn[.]shop, nutatedtriol[.]com, mixscoggan[.]shop, bu[.]unrimedironize[.]shop |
| FakeCaptcha Redirectors | actednow[.]com/675cb495c39bc481ddf8edd6, buzzflying[.]shop/6767af2ee2aa535e92d62a64, goldtera[.]live/6758b1d6467532a801fa06c4, orbito[.]online/677120fb2cca41d88a7392a2, bestfree4u[.]com, avs4u[.]net/, arcadeclassic[.]org |
| FakeCaptcha Landing Pages | adelaidavizcaino[.]com/cpw, partage-de-medias[.]fly[.]storage[.]tigris[.]dev/affiliate-link[.]html, finding-from-internet[.]fly[.]storage[.]tigris[.]dev/seacrh-result[.]html |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update