logo

OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet

ID: 01546426-ba9a-51da-bf37-5f165a037b58

STIX ID: report--01546426-ba9a-51da-bf37-5f165a037b58

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

OCRFix is a deceptive multi-stage malware campaign that impersonates the Tesseract OCR project via a typosquatted site and LLM-poisoned search results. Victims are tricked with a faux CAPTCHA to paste a PowerShell command, which launches a loader that retrieves further stages; subsequent payloads create persistence, disable defenses (including Windows Defender exclusions and BitLocker weakening), and install a listener that contacts C2 endpoints hidden in BNB Smart Chain TestNet smart contracts ("EtherHiding") for remote control and botnet use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.