216.73.216.6

Botnet Trojan delivered through ClickFix and EtherHiding

· Published 27/02/2026 09:28 · Modified 27/02/2026 10:00

Export JSON

Essential information

Published
27/02/2026 09:28
Modified
27/02/2026 10:00
Tags
2026-02-27 bnb smart chain botnet clickfix defense evasion etherhiding multi-stage obfuscation ocrfix phishing typosquatting
Related entities
7 observables, 13 techniques (mitre), 1 malware, 9 others

Description

A sophisticated campaign impersonating Tesseract OCR was discovered, utilizing and techniques. The attack chain, named , employed malware deployments with heavy and techniques, including . The campaign used TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like and the importance of robust defenses.

External references