PULSE NAME
Botnet Trojan delivered through ClickFix and EtherHiding
WHITE AlienVault 2026-02-27 Modified: 2026-02-27
25
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses.
Indicators of Compromise (4 / 25 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 20b8714b6e0f2459a21b8e315b79d290 2026-02-27
FileHash-MD5 3536f953ee2381215ecc1001653b03c2 2026-02-27
FileHash-MD5 b5ad76ef744401aa648f56a83e0db00c 2026-02-27
FileHash-MD5 e2d8dac1c3fe671f4244198953759827 2026-02-27