logo

Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain

ID: ef8d6b54-4aca-5c41-b864-3b33f57f8bd1

STIX ID: report--ef8d6b54-4aca-5c41-b864-3b33f57f8bd1

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers uncovered OCRFix, a sophisticated three-stage botnet active as of March 3, 2026, that uses a social-engineering fake CAPTCHA (ClickFix) to trick victims into running a malicious PowerShell/MSI dropper. The botnet stores its C2 URLs inside BNB Smart Chain testnet smart contracts ("EtherHiding") so infrastructure can be rotated via blockchain transactions without updating binaries; stages are VBScript-based (downloader, escalation/persistence, and final C2 agent) and check in regularly for operator commands. Analysis found Russian-language artifacts in the panel and developers' comments. Because C2 resolution occurs via legitimate blockchain nodes and JSON-RPC responses, standard network blocking and content inspection are often ineffective; defenders are advised to monitor interactions with known BSC testnet contracts and inspect JSON-RPC responses for encoded URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.