Abstract illustration of interlocking angular outlines in violet and cyan, streaked with diagonal light on a dark navy background

FakeCAPTCHA PDFs Ride a Trusted CDN to Beat Domain Allowlisting

Netskope Threat Labs has traced more than 12,700 near-identical FakeCAPTCHA documents back to a single automated production line, hosted on a commonly allowlisted content delivery network.

The files sit on Webflow’s content delivery network (cdn.prod.website-files.com) and get picked up by Google as innocuous “upgrade guides,” according to Netskope’s Aug. 4 research. Each PDF shows a fake “I’m not a robot” prompt that feeds users into a traffic-distribution system, a for-hire routing layer built on a custom Elixir/Phoenix stack rather than an off-the-shelf kit. Netskope says the operation has run for over 14 months and remains active, with new lure domains registered as recently as this month.

The TDS runs sequential filters: it blocks datacenter IPs during the TLS handshake, issues a Cloudflare Turnstile challenge to weed out bots, and applies geographic and device checks. Real users in target regions get pushed to malware or scam operators; everyone else gets sent to an ad lander so the operator monetizes the click either way.

This technique bypasses standard source-reputation checks. Because the lures live on a clean, commonly allowlisted CDN, URL and domain filtering alone will miss them, and content-level inspection becomes necessary. The datacenter-IP filtering also means many sandboxes and scanners get routed away from the payload, producing false negatives in detection testing.

One caveat: the figures and timeline are single-sourced to Netskope, with no independent corroboration yet found.


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading