
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick users into costly actions, and browser push-notification scams that create a persistent channel for fraud messages.
A threat landscape report describes how cybercrime capabilities are increasingly sold or rented as services, allowing even low-skilled actors to operate at scale with anonymity and short-lived infrastructure. Two repeatable web-based scams stand out. The first uses a fake CAPTCHA or human-verification page that tricks mobile users into taking an action that triggers costly international text messages, with one observed case generating about 60 messages and roughly $30 in charges. The second uses a similar fake verification, cookie banner, or CAPTCHA prompt to get users to click Allow on browser notifications. Once granted, that permission becomes a persistent channel attackers use to flood victims with scam notifications, in some cases more than 140 per day promoting investment scams, gambling sites, fake antivirus alerts, and government impersonation content.
These scams work because they exploit routine, low-friction interactions that people rarely question: clicking through a CAPTCHA or approving a notification permission. Attackers also build lookalike lure pages that replicate branding, logos, and user experience closely enough that victims trust them without checking the underlying domain. AI is also being used to automate reconnaissance and generate more convincing lures, while cloaking, redirect chains, and fast domain rotation, with some phishing pages lasting under 24 hours, make detection and takedown harder.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It refers to criminals buying or renting phishing, fraud, malware, and hidden infrastructure as ready-made services, which lets even low-skilled actors run scams at scale with anonymity and short-lived infrastructure.
A fraudulent human-verification page tricks a mobile user into an action that triggers expensive international text messages, with one observed case generating about 60 messages costing about $30.
Clicking Allow on a fake CAPTCHA, cookie banner, or verification prompt gives attackers a persistent channel to the device, and some victims received more than 140 scam notifications per day.
Yes, executives are exploited in impersonation fraud, business email compromise, and other social engineering schemes because of their identities and access.
You tap a simple CAPTCHA on your phone… and 60 international texts go out, costing you thirty bucks. One tap. This is cybercrime-as-a-service: rented fake CAPTCHA pages and push-notification scams that look legit, then quietly send paid SMS or flood you with 140 scam alerts a day. Here’s the trick: criminals buy ready-made kits that clone real sites, rotate domains every day, and use fake CAPTCHAs or cookie banners to make you tap Verify or Allow without thinking. Your move: if a CAPTCHA or verification makes your device send messages or asks to turn on notifications, stop and close the page, don’t tap Allow, don’t tap Verify.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Cofense reports that attackers target finance teams with phishing emails designed to look like normal invoices, contracts, and payment notices, not urgent “act…

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…