Fake CAPTCHA, Real Business: Traffic Distribution for Hire

Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A single PDF factory has produced more than 12,700 structurally similar FakeCaptcha documents on Webflow’s CDN, where they appear in Google search as ordinary “upgrade guides” and feed a traffic-distribution system. The campaign routes qualified visitors to malware, scam, or reseller infrastructure while using rotated lure domains, ww80/wwNN routers, and a custom Elixir/Phoenix gate to keep the operation active. #FakeCaptcha #Webflow #GoogleGemini #Claude #LegionLoader #berapt-medii #yfdpco

Keypoints

  • More than 12,700 FakeCaptcha PDFs were stamped out by one factory and hosted on Webflow’s CDN.
  • The documents are indexed by Google as benign “upgrade guides,” helping the campaign attract clicks from search results.
  • Each PDF contains a fake CAPTCHA that sends visitors into a traffic-distribution system (TDS).
  • The gate uses a custom Elixir/Phoenix stack with IP/ASN filtering, Cloudflare Turnstile, JWT checks, and geo/device routing.
  • Qualified traffic is routed to multiple downstream destinations, including malware distribution, scam infrastructure, and other buyers.
  • Observed branches include the Legion Loader hub, a TDS reseller gate on yfdpco domains, and a premium-SMS subscription scam flow.
  • The operation has been active for more than 14 months and continues to rotate lure domains and infrastructure.

MITRE Techniques

  • [T1566 ] Phishing – Uses deceptive PDF “upgrade guides” and fake CAPTCHA pages to lure victims into clicking through the chain. (‘A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents…’)
  • [T1189 ] Drive-by Compromise – Victims are routed from a search result or PDF click into the TDS without realizing the malicious redirection. (‘Clicking it enters the TDS, where a ww80/wwNN traffic router… decides who you are.’)
  • [T1036 ] Masquerading – The files are made to look like ordinary documentation and “upgrade guides” on a trusted CDN. (‘Google indexes them as ordinary “upgrade guides.”’)
  • [T1583.001 ] Acquire Infrastructure: Domains – The operators register and reuse lure domains and front-door entries for the campaign. (‘The 2025 lure domains… have given way to a 2026 pool: nurepikis[.]com, tugoduzak[.]com…’)
  • [T1090 ] Proxy: Traffic Distribution System – A TDS filters and routes visitors to different downstream destinations based on profile checks. (‘Each document is a doorway into a traffic-distribution system (TDS) that sorts visitors and routes those that qualify…’)
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The campaign uses web-based routing, redirects, and CDN-hosted landing pages to move traffic between stages. (‘The PDF shows an “I’m not a robot” panel… Clicking it enters the TDS…’)
  • [T1056.001 ] Input Capture: Keylogging – The fake CAPTCHA and clipboard-hijack flow coerce user interaction and command entry for payload installation. (‘…telling the victim to press Win+R and paste a command that installs an MSI…’)
  • [T1112 ] Modify Registry – Not explicitly stated; no clear registry activity is described in the article. (‘No direct registry modification detail provided.’)
  • [T1204 ] User Execution – The attack depends on the user clicking the fake CAPTCHA and following the prompted steps. (‘Clicking it enters the TDS…’)
  • [T1204.001 ] User Execution: Malicious Link – Users follow a search result, PDF link, or embedded link to reach the gate. (‘A query as mundane as “upgrade guide” filetype:pdf… surfaces these documents…’)
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – Not explicitly named in the article, but the Win+R paste-and-run delivery pattern indicates command execution via shell. (‘…press Win+R and paste a command…’)
  • [T1647 ] Stolen Cookie Replay – Not mentioned; no evidence of cookie theft/replay in the article. (‘No cookie-theft behavior described.’)

Indicators of Compromise

  • [Domains ] FakeCaptcha lure and routing infrastructure – dutabuz[.]com, zuwufag[.]com, nurepikis[.]com, tugoduzak[.]com
  • [Domains ] Additional lure and payload-related domains – maxudijuz[.]com, pofezaf[.]com, binonelola[.]com, berapt-medii[.]com
  • [Domains ] TDS and scam infrastructure – yfdpco1[.]com, yfdpco4[.]com, scorenetsystems[.]pro, chromovira[.]org, solidlinkpro[.]info
  • [IP Addresses ] TDS and backend infrastructure – 212.92.104[.]119, 185.53.179[.]200, 208.91.196[.]46
  • [IP Addresses ] Additional infrastructure – 188.72.236[.]249
  • [File Hashes ] FakeCaptcha PDF structural fingerprints / exact matches – T1796401078D050ED3E05D43A6BD172D5C0F0A7B48C5C63AFF61661FCBBA186269D8E4AE, 9a448a3f5689bff73158220126cca1085
  • [File Hashes ] Cluster and sample hash – 9cacf340f36958ada8f48cd21217732cf, 87b8b76762eac941c562c6c8eefb8402f48fc70fcfe360a274b12e75dd5726e2
  • [File Names ] Payload sample – Documentos[.]pdf.exe
  • [URLs / Parameters ] Premium-SMS subscription trigger – sms:797079&body=ALTA
  • [File/Traffic Context ] Traffic router and gate artifacts – ww80[.]tugoduzak[.]com, ww19[.]nurepikis[.]com, sk-park[.]php


Read more: https://www.netskope.com/blog/fake-captcha-real-business-traffic-distribution-for-hire