logo

OCRFix Botnet Trojan Leveraging ClickFix Phishing and EtherHiding to Conceal Blockchain-Based Command Infrastructure

ID: 54bbb878-17cc-56fa-9f5e-7257ec160499

STIX ID: report--54bbb878-17cc-56fa-9f5e-7257ec160499

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**OCRFix botnet trojan campaign:** A multi-stage malware campaign uses a typosquatted tesseract-ocr.com site, SEO/LLM poisoning and a fake CAPTCHA to trick users into pasting an obfuscated PowerShell command that retrieves and runs an MSI. The MSI deploys three stages (loader querying BNB TestNet smart contracts for C2, a persistence/setup helper that creates high-privilege scheduled tasks and Defender exclusions, and a bot listener that harvests host identifiers and reports to a control panel), while EtherHiding on the BNB Smart Chain TestNet provides resilient, updateable C2 addresses; indicators include opsecdefcloud.com, ldture.com, 98166e51.msi and use of bsc-testnet.publicnode.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.