Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
ID: ef8d6b54-4aca-5c41-b864-3b33f57f8bd1
STIX ID: report--ef8d6b54-4aca-5c41-b864-3b33f57f8bd1
Feed Name: securityonline.info
Researchers uncovered OCRFix, a sophisticated three-stage botnet active as of March 3, 2026, that uses a social-engineering fake CAPTCHA (ClickFix) to trick victims into running a malicious PowerShell/MSI dropper. The botnet stores its C2 URLs inside BNB Smart Chain testnet smart contracts ("EtherHiding") so infrastructure can be rotated via blockchain transactions without updating binaries; stages are VBScript-based (downloader, escalation/persistence, and final C2 agent) and check in regularly for operator commands. Analysis found Russian-language artifacts in the panel and developers' comments. Because C2 resolution occurs via legitimate blockchain nodes and JSON-RPC responses, standard network blocking and content inspection are often ineffective; defenders are advised to monitor interactions with known BSC testnet contracts and inspect JSON-RPC responses for encoded URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
