OCRFix Botnet Uses ClickFix Phishing and EtherHiding to Mask Blockchain C2 Infrastructure
ID: f685a0fc-e658-57d9-b00e-8bc3577be221
STIX ID: report--f685a0fc-e658-57d9-b00e-8bc3577be221
Feed Name: GBHackers
Threat Score
OCRFix is a multi-stage botnet Trojan delivered through a typosquatted Tesseract OCR site that tricks users into pasting PowerShell commands; the attack chain drops an MSI that installs three staged executables (loader, persistence/evader, bot listener). Operators use EtherHiding on the BNB Smart Chain to host rotating C2 data, and the malware disables defenses, adds Defender exclusions, and beacons periodically; the report includes domains and SHA1 IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
