#infobloxthreatintel — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #infobloxthreatintel, aggregated by home.social.
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf