logo

OCRFix Botnet Uses ClickFix Phishing and EtherHiding to Mask Blockchain C2 Infrastructure

ID: f685a0fc-e658-57d9-b00e-8bc3577be221

STIX ID: report--f685a0fc-e658-57d9-b00e-8bc3577be221

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

OCRFix is a multi-stage botnet Trojan delivered through a typosquatted Tesseract OCR site that tricks users into pasting PowerShell commands; the attack chain drops an MSI that installs three staged executables (loader, persistence/evader, bot listener). Operators use EtherHiding on the BNB Smart Chain to host rotating C2 data, and the malware disables defenses, adds Defender exclusions, and beacons periodically; the report includes domains and SHA1 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.