Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.
AI Analysis
Technical Summary
This threat involves a traffic distribution system abusing search engine optimization and AI assistant exposure to deliver malicious PDFs containing fake CAPTCHA panels. These PDFs are hosted on Webflow's CDN and redirect users through a custom Elixir/Phoenix backend that filters traffic by IP, bot detection, and geography. The system directs qualifying users to three main endpoints: Legion Loader malware distribution, a traffic distribution system (TDS) reseller gate, and premium SMS subscription scams aimed at Spanish-speaking victims. Non-qualifying users are monetized via search-arbitrage advertising. The operation has been ongoing for over 14 months and uses over 12,700 structurally similar PDFs, indicating a large-scale, persistent campaign. The threat leverages multiple adversary techniques including search engine poisoning, traffic distribution, and social engineering via fake CAPTCHA challenges.
Potential Impact
Victims are exposed to malware infections (Legion Loader), traffic distribution system reseller infrastructure, and premium SMS subscription scams, potentially leading to malware compromise, financial fraud, and unwanted premium charges. The campaign abuses legitimate CDN hosting and search engine results, increasing the likelihood of victim exposure. The targeting of English-speaking countries and Spanish-speaking users for specific scams indicates a broad and segmented impact. The operation monetizes non-qualifying traffic through advertising, indicating a financially motivated and scalable threat.
Mitigation Recommendations
No official patch or fix is applicable as this is an abuse of legitimate services and search engine results rather than a software vulnerability. Mitigation should focus on user awareness to avoid interacting with suspicious CAPTCHA PDFs and domains listed as indicators. Security teams should block or monitor traffic to the identified malicious domains and hashes. Organizations should consider enhancing detection of traffic distribution system activity and premium SMS scams. Since the threat abuses Webflow's CDN, reporting abuse to the CDN provider may help disrupt hosting. There is no indication that vendor-side fixes or patches are available. Patch status is not applicable.
Affected Countries
United States, Australia, British Indian Ocean Territory, Canada, India
Indicators of Compromise
- domain: berapt-medii.com
- domain: zuwufag.com
- hash: f40c47b9d68ea251957b705c851a6ee9
- hash: 67ef6e09000a5ae837faecd579deb331035d6717
- hash: 87b8b76762eac941c562c6c8eefb8402f48fc70fcfe360a274b12e75dd5726e2
- domain: binonelola.com
- domain: bovetewa.com
- domain: dutabuz.com
- domain: gowixese.com
- domain: jufewine.com
- domain: pofezaf.com
- domain: riwitamo.com
- domain: scorenetsystems.pro
- domain: solidlinkpro.info
- domain: vimemug.com
- domain: ww19.nurepikis.com
- domain: ww80.tugoduzak.com
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
Description
A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a traffic distribution system abusing search engine optimization and AI assistant exposure to deliver malicious PDFs containing fake CAPTCHA panels. These PDFs are hosted on Webflow's CDN and redirect users through a custom Elixir/Phoenix backend that filters traffic by IP, bot detection, and geography. The system directs qualifying users to three main endpoints: Legion Loader malware distribution, a traffic distribution system (TDS) reseller gate, and premium SMS subscription scams aimed at Spanish-speaking victims. Non-qualifying users are monetized via search-arbitrage advertising. The operation has been ongoing for over 14 months and uses over 12,700 structurally similar PDFs, indicating a large-scale, persistent campaign. The threat leverages multiple adversary techniques including search engine poisoning, traffic distribution, and social engineering via fake CAPTCHA challenges.
Potential Impact
Victims are exposed to malware infections (Legion Loader), traffic distribution system reseller infrastructure, and premium SMS subscription scams, potentially leading to malware compromise, financial fraud, and unwanted premium charges. The campaign abuses legitimate CDN hosting and search engine results, increasing the likelihood of victim exposure. The targeting of English-speaking countries and Spanish-speaking users for specific scams indicates a broad and segmented impact. The operation monetizes non-qualifying traffic through advertising, indicating a financially motivated and scalable threat.
Defensive Guidance
No official patch or fix is applicable as this is an abuse of legitimate services and search engine results rather than a software vulnerability. Mitigation should focus on user awareness to avoid interacting with suspicious CAPTCHA PDFs and domains listed as indicators. Security teams should block or monitor traffic to the identified malicious domains and hashes. Organizations should consider enhancing detection of traffic distribution system activity and premium SMS scams. Since the threat abuses Webflow's CDN, reporting abuse to the CDN provider may help disrupt hosting. There is no indication that vendor-side fixes or patches are available. Patch status is not applicable.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.netskope.com/blog/fake-captcha-real-business-traffic-distribution-for-hire"]
- Adversary
- null
- Pulse Id
- 6a734a570822e0edf4d1fdb5
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainberapt-medii.com | — | |
domainzuwufag.com | — | |
domainbinonelola.com | — | |
domainbovetewa.com | — | |
domaindutabuz.com | — | |
domaingowixese.com | — | |
domainjufewine.com | — | |
domainpofezaf.com | — | |
domainriwitamo.com | — | |
domainscorenetsystems.pro | — | |
domainsolidlinkpro.info | — | |
domainvimemug.com | — | |
domainww19.nurepikis.com | — | |
domainww80.tugoduzak.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashf40c47b9d68ea251957b705c851a6ee9 | — | |
hash67ef6e09000a5ae837faecd579deb331035d6717 | — | |
hash87b8b76762eac941c562c6c8eefb8402f48fc70fcfe360a274b12e75dd5726e2 | — |
Threat ID: 6a744c2ebf8831d539758e70
Added to database: 08/06/2026, 08:56:14 UTC
Last enriched: 08/06/2026, 11:33:07 UTC
Last updated: 08/06/2026, 17:53:02 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.