Threat actors don’t need sophisticated malware when a fake CAPTCHA check generates international SMS charges automatically. That’s the core mechanic of the IRSF campaign Infoblox just detailed, and it’s a clean reminder that fraud at scale runs on volume, not complexity.

SIM card used in IRSF telecom fraud campaigns
International Revenue Share Fraud campaigns use leased phone numbers to siphon charges through unwitting users.

The same week, the U.S. government announced a sweeping crackdown on Southeast Asian scam networks operating under the protection of politically connected figures. Different mechanisms, same underlying architecture: automated abuse of network infrastructure at massive scale. Your perimeter controls either handle that scale or they don’t.

How the IRSF and Scam Center Threat Actually Works

International Revenue Share Fraud is not glamorous. A threat actor leases a block of phone numbers tied to premium-rate routes, then drives traffic to those numbers artificially. The fake CAPTCHA variant Infoblox documented pushes users into triggering outbound SMS to those numbers, which generates per-message charges that flow back to the fraud operator. No credentials stolen, no ransomware deployed. Pure infrastructure abuse.

Infoblox tied 120 distinct Keitaro traffic distribution system campaigns to this operation.

Keitaro is a legitimate traffic management tool, and that’s the point. Attackers rent commodity infrastructure, route it through respectable-looking intermediaries, and collect at the other end. The Southeast Asian scam compounds the U.S. Treasury just sanctioned operate with similar logic at a bigger scale: rent people, rent servers, rotate IP space, and keep the fraud pipeline moving. These aren’t hackers huddled in a basement. They’re operations with HR departments.

US government crackdown on Southeast Asia cyberscam operations
U.S. officials have framed the Southeast Asia scam center crackdown as a new front in the fight against Chinese transnational organized crime.

The thread connecting both threats is ipban: every fraud operation of this type depends on the ability to make high volumes of requests or connections from rotating IP space without getting cut off. Slow or absent IP-layer response is the gap they’re exploiting.

What Your Firewall Can and Cannot Do Here

Standard firewall rules handle known-bad IPs reasonably well. The problem is that IRSF operators and scam compound infrastructure don’t stay on known-bad lists for long. They rotate through cloud provider IP ranges, residential proxies, and compromised hosts in ways that outpace manual blocklist updates by days or weeks.

Behavioral detection is where static rules run out of road.

A firewall rule blocking a specific IP does nothing when the next request comes from a clean AWS or Azure egress address. What you actually need is rate-based behavioral logic that flags the pattern, whether it’s repeated CAPTCHA endpoint hits, rapid-fire SMS API calls, or authentication probes that look too uniform to be human. The threat detection layer has to work faster than the attacker’s IP rotation cycle.

  • Watch for abnormal volumes of requests to CAPTCHA endpoints or SMS verification APIs
  • Flag IP ranges that generate multiple failed or rapid-fire auth attempts across short windows
  • Cross-reference egress traffic against known traffic distribution infrastructure like Keitaro
  • Maintain separation between your rate-limiting logic and your static blocklist so each can be tuned independently
  • Review outbound SMS and toll-number call patterns from any internal systems that accept user-triggered communications

Concrete Steps to Harden Your Edge Against Fraud Infrastructure

Start with your own exposure surface before worrying about blocklists.

If your application triggers any kind of SMS or phone verification flow, that flow is a candidate for IRSF abuse. Attackers don’t need to breach your authentication system; they need to reach the SMS trigger endpoint enough times to rack up charges on premium-rate numbers they control. Rate limiting that endpoint with aggressive thresholds and per-IP quotas is the single fastest risk reduction you can make. Combine that with phone number validation that rejects known premium-rate prefixes before the SMS is ever sent.

For brute-force and credential stuffing exposure, automated ipban tooling earns its keep here. Behavioral blocking that escalates from rate-limiting to full IP bans based on failure patterns cuts off the enumeration phase before attackers get useful signal. IPBan Pro extends this with real-time threat intelligence feeds that flag infrastructure associated with fraud campaigns, which shortens the window between a new rotation and a block.

At the network layer, tighten egress filtering. Scam compound infrastructure often uses domain generation algorithms or fast-flux DNS, both of which leave detectable patterns in DNS query logs. A defense in depth approach means your threat protection doesn’t hinge on a single control catching the traffic; it means multiple layers each degrade the operation a little, and together they make it uneconomical.

For incident response, if you suspect IRSF abuse, pull your SMS provider logs immediately. Look for spikes in outbound messages to unfamiliar country codes or number ranges. Your provider can often flag premium-rate destination numbers; ask them explicitly if that reporting exists in your account dashboard.

One more thing worth saying plainly: security hardening against these operations is not a one-time configuration. Fraud networks retool constantly. Your blocking logic needs a review cycle on the same cadence as your threat intelligence updates, which in practical terms means at least monthly, and more often if you’re in telecom, fintech, or any sector that processes high volumes of user-initiated communications.

Frequently Asked Questions

What is IRSF and why is it hard to detect?
International Revenue Share Fraud routes artificial traffic to premium-rate phone numbers the attacker controls, generating per-message revenue. It’s hard to detect because it uses legitimate infrastructure like SMS APIs and traffic distribution systems, and leaves no malware footprint on victim devices.
Does ipban help against IRSF campaigns?
Yes, but only at the IP layer. Automated IP banning disrupts the enumeration and high-volume request phases of these campaigns. It needs to be paired with application-level rate limiting and SMS endpoint validation to address the full attack surface.
How do Southeast Asian scam compounds evade detection?
They operate like businesses, with rotating infrastructure, staff working in shifts, and commodity cloud services that blend their traffic with legitimate sources. Behavioral detection and threat intelligence feeds that track fraud-affiliated infrastructure are more effective than static blocklists against this model.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.