Botnet Trojan delivered through ClickFix and EtherHiding
Essential information
- Published
- 27/02/2026 09:28
- Modified
- 27/02/2026 10:00
- Tags
- 2026-02-27 bnb smart chain botnet clickfix defense evasion etherhiding multi-stage obfuscation ocrfix phishing typosquatting
- Related entities
- 7 observables, 13 techniques (mitre), 1 malware, 9 others
Description
A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses.