OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet
ID: 01546426-ba9a-51da-bf37-5f165a037b58
STIX ID: report--01546426-ba9a-51da-bf37-5f165a037b58
Feed Name: securityonline.info
OCRFix is a deceptive multi-stage malware campaign that impersonates the Tesseract OCR project via a typosquatted site and LLM-poisoned search results. Victims are tricked with a faux CAPTCHA to paste a PowerShell command, which launches a loader that retrieves further stages; subsequent payloads create persistence, disable defenses (including Windows Defender exclusions and BitLocker weakening), and install a listener that contacts C2 endpoints hidden in BNB Smart Chain TestNet smart contracts ("EtherHiding") for remote control and botnet use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
