Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Fake CAPTCHA, Real Business: Traffic Distribution for Hire

0
Medium
Published: 08/05/2026 (08/05/2026, 14:36:07 UTC)
Source: AlienVault OTX General

Description

A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 11:33:07 UTC

Technical Analysis

This threat involves a traffic distribution system abusing search engine optimization and AI assistant exposure to deliver malicious PDFs containing fake CAPTCHA panels. These PDFs are hosted on Webflow's CDN and redirect users through a custom Elixir/Phoenix backend that filters traffic by IP, bot detection, and geography. The system directs qualifying users to three main endpoints: Legion Loader malware distribution, a traffic distribution system (TDS) reseller gate, and premium SMS subscription scams aimed at Spanish-speaking victims. Non-qualifying users are monetized via search-arbitrage advertising. The operation has been ongoing for over 14 months and uses over 12,700 structurally similar PDFs, indicating a large-scale, persistent campaign. The threat leverages multiple adversary techniques including search engine poisoning, traffic distribution, and social engineering via fake CAPTCHA challenges.

Potential Impact

Victims are exposed to malware infections (Legion Loader), traffic distribution system reseller infrastructure, and premium SMS subscription scams, potentially leading to malware compromise, financial fraud, and unwanted premium charges. The campaign abuses legitimate CDN hosting and search engine results, increasing the likelihood of victim exposure. The targeting of English-speaking countries and Spanish-speaking users for specific scams indicates a broad and segmented impact. The operation monetizes non-qualifying traffic through advertising, indicating a financially motivated and scalable threat.

Defensive Guidance

No official patch or fix is applicable as this is an abuse of legitimate services and search engine results rather than a software vulnerability. Mitigation should focus on user awareness to avoid interacting with suspicious CAPTCHA PDFs and domains listed as indicators. Security teams should block or monitor traffic to the identified malicious domains and hashes. Organizations should consider enhancing detection of traffic distribution system activity and premium SMS scams. Since the threat abuses Webflow's CDN, reporting abuse to the CDN provider may help disrupt hosting. There is no indication that vendor-side fixes or patches are available. Patch status is not applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.netskope.com/blog/fake-captcha-real-business-traffic-distribution-for-hire"]
Adversary
null
Pulse Id
6a734a570822e0edf4d1fdb5
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainberapt-medii.com
domainzuwufag.com
domainbinonelola.com
domainbovetewa.com
domaindutabuz.com
domaingowixese.com
domainjufewine.com
domainpofezaf.com
domainriwitamo.com
domainscorenetsystems.pro
domainsolidlinkpro.info
domainvimemug.com
domainww19.nurepikis.com
domainww80.tugoduzak.com

Hash

ValueDescriptionCopy
hashf40c47b9d68ea251957b705c851a6ee9
hash67ef6e09000a5ae837faecd579deb331035d6717
hash87b8b76762eac941c562c6c8eefb8402f48fc70fcfe360a274b12e75dd5726e2

Threat ID: 6a744c2ebf8831d539758e70

Added to database: 08/06/2026, 08:56:14 UTC

Last enriched: 08/06/2026, 11:33:07 UTC

Last updated: 08/06/2026, 17:53:02 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses