Threat reportMalwareTL-2026-0162

Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites with PowerShell Payload Chaining and Defense Evasion

highSUPERSEDED

Tesseract OCR Typosquat Campaign (TL-2026-0162), also tracked as Tesseract OCR ClickFix, is a high-severity malware campaign, first published 2026-03-01. It has no confirmed attribution, affects Tesseract OCR Project Tesseract OCR (impersonated), maps to 24 MITRE ATT&CK techniques (T1005, T1027, T1027.010), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0162

Threat ID
TL-2026-0162
Also known as
Tesseract OCR ClickFix, Tesseract Typosquat Campaign
Severity
HIGH
Status
SUPERSEDED
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, research, education, financial
Target regions
Global
Detection rules
9
Indicators of compromise
16

How Tesseract OCR Typosquat Campaign works

A targeted phishing campaign impersonates the legitimate Tesseract OCR open-source project (60K+ GitHub stars) through typosquatted domains, using ClickFix-style social engineering to trick developers into executing PowerShell commands that deploy multi-stage malware. The campaign features heavy obfuscation, anti-analysis techniques, clipboard hijacking for payload delivery, and multiple defense evasion mechanisms including AMSI bypass, ETW patching, and environment fingerprinting.

A sophisticated malware campaign targets developers and power users searching for Tesseract OCR — the widely-used open-source Optical Character Recognition engine originally developed by HP Labs and later maintained by Google, with over 60,000 GitHub stars and millions of downloads. The campaign uses typosquatted domains that closely mimic the legitimate tesseract-ocr.github.io documentation site and official download pages.

**Attack Chain Overview**: Victims searching for Tesseract OCR downloads, documentation, or Windows installers are redirected to convincing typosquatted sites. These sites present a ClickFix-style interaction — a fake error dialog, CAPTCHA verification, or "system check" that instructs the user to open the Windows Run dialog (Win+R) and paste a command that has been silently copied to their clipboard. The clipboard payload is a PowerShell one-liner that initiates a multi-stage malware delivery chain.

**ClickFix Social Engineering Evolution**: This campaign represents an evolution of the ClickFix technique (first documented in 2024), which has rapidly become one of the most prevalent social engineering methods. Unlike earlier ClickFix campaigns that used generic "browser update" or "verification" pretexts, this variant specifically targets the developer community by impersonating a legitimate open-source tool. The ClickFix approach bypasses traditional email-based phishing defenses because the victim voluntarily executes the payload — no exploit, no attachment, no macro.

**Multi-Stage Payload Delivery**: - **Stage 1 (Clipboard + Run Dialog)**: PowerShell one-liner copied to clipboard via JavaScript. Uses window.navigator.clipboard.writeText() or document.execCommand('copy') to silently stage the payload. The command uses -ExecutionPolicy Bypass -WindowStyle Hidden to execute silently. - **Stage 2 (Downloader)**: The initial PowerShell downloads an obfuscated script from attacker infrastructure. The script uses Base64 encoding layered with XOR obfuscation and string concatenation to evade static detection. - **Stage 3 (Environment Check)**: Before deploying the final payload, the malware performs environment fingerprinting — checking for virtual machines (VMware, VirtualBox, Hyper-V via WMI queries), sandbox environments (checking for common analysis tools like Wireshark, Process Monitor, IDA Pro), and security products. It also checks the number of running processes, installed software count, and system uptime to detect automated analysis. - **Stage 4 (Defense Evasion)**: The malware implements AMSI bypass (patching AmsiScanBuffer in amsi.dll), ETW patching (disabling Event Tracing for Windows to blind EDR), and Windows Defender exclusion path addition via PowerShell (Add-MpPreference -ExclusionPath). - **Stage 5 (Final Payload)**: Deploys an information stealer targeting browser credentials, cryptocurrency wallets, SSH keys, and developer tokens (GitHub, GitLab, npm, PyPI API tokens). Also establishes persistence via scheduled tasks and startup folder shortcuts.

**Typosquatting Domains**: The campaign registers domains that closely resemble legitimate Tesseract OCR infrastructure: - tesseract-ocr[.]org (vs. legitimate tesseract-ocr.github.io) - tesseractocr[.]download - tesseract-download[.]com - tesseract-ocr-installer[.]com - ocr-tesseract[.]com These domains use valid HTTPS certificates (Let's Encrypt), professional-looking landing pages cloned from the real site, and SEO poisoning to appear in search results.

**Developer-Specific Targeting**: Unlike generic ClickFix campaigns, this variant specifically targets the developer ecosystem. Tesseract OCR is used extensively in document processing pipelines, data extraction workflows, and CI/CD systems. Compromising developer machines provides access to source code repositories, cloud credentials, API tokens, and CI/CD pipeline secrets.

**Obfuscation Techniques**: The PowerShell payloads use multiple layers of obfuscation: (1) Base64 encoding with -EncodedCommand, (2) String concatenation and variable substitution ('I'+'EX'), (3) Character code conversion ([char]73+[char]69+[char]88), (4) Environment variable abuse ($env:comspec), (5) Invoke-Expression aliasing via Set-Alias. Each stage is independently obfuscated with different techniques to defeat signature-based detection.

**Relationship to Prior ClickFix Campaigns**: This campaign shares infrastructure patterns with earlier ClickFix operations documented in TL-2026-0118, TL-2026-0120, and TL-2026-0127 (browser cache smuggling). The evolution from generic "browser update" pretexts to targeted developer tool impersonation represents a significant tactical advancement in the ClickFix ecosystem.

**Impact Assessment**: Developers who execute the payload face compromise of their entire development environment — source code, credentials, API tokens, SSH keys, and potentially CI/CD pipeline access. For enterprise developers, this can lead to supply chain compromise if attacker gains access to package registries or build systems.

MITRE ATT&CK techniques used in TL-2026-0162

collection

T1005 Data from Local System; T1115 Clipboard Data

stealth

T1027 Obfuscated Files or Information; T1027.010 Command Obfuscation; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053.005 Scheduled Task; T1059.001 PowerShell; T1204.001 Malicious Link; T1204.002 Malicious File

discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

initial-access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

persistence

T1547.001 Registry Run Keys / Startup Folder

credential-access

T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers

resource-development

T1583.001 Domains; T1608.006 SEO Poisoning

defense-impairment

T1685 Disable or Modify Tools; T1685.001 Disable or Modify Windows Event Log

Affected products and versions in Tesseract OCR Typosquat Campaign

  • Tesseract OCR Project — Tesseract OCR (impersonated)
    Vulnerable versions: All — typosquatted download sites target any user searching for Tesseract
    Fixed in: Official: github.com/tesseract-ocr/tesseract
  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2016+
  • Multiple — Developer Workstations
    Vulnerable versions: Any developer downloading OCR tools from search results

Remediation for Tesseract OCR Typosquat Campaign

Immediate actions

  • Block known typosquatted Tesseract OCR domains at DNS/proxy level
  • Alert developers to only download Tesseract OCR from github.com/tesseract-ocr/tesseract
  • Hunt for PowerShell -ExecutionPolicy Bypass -WindowStyle Hidden executions on developer workstations
  • Check clipboard history tools for suspicious PowerShell payloads
  • Scan for AMSI bypass indicators (AmsiScanBuffer patching)
  • Monitor for Add-MpPreference -ExclusionPath commands
  • Review scheduled tasks and startup folder for recently added persistence

Workarounds

  • Disable clipboard access from JavaScript in browser security settings
  • Block PowerShell -EncodedCommand via AppLocker or WDAC policies
  • Restrict Win+R Run dialog via Group Policy where appropriate

Longer-term hardening

  • Implement application whitelisting on developer workstations
  • Deploy PowerShell Constrained Language Mode where possible
  • Enable enhanced PowerShell Script Block Logging (Event ID 4104)
  • Implement DNS filtering with typosquat detection capability
  • Deploy browser extensions that warn on known-bad domains
  • Educate developers on ClickFix social engineering techniques
  • Monitor for credential access to package registry tokens (npm, PyPI, GitHub)

Weaknesses (CWE) in Tesseract OCR Typosquat Campaign

CWE-451, CWE-494, CWE-693

Timeline of Tesseract OCR Typosquat Campaign

  • ClickFix social engineering technique first documented — trick users into executing PowerShell/shell commands via fake error dialogs, CAPTCHAs, or update prompts.
  • ConsentFix variant discovered — abuses Azure CLI OAuth app to hijack Microsoft accounts without passwords. Source: https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/
  • ErrTraffic ClickFix-as-a-Service platform discovered — automates ClickFix attacks via fake browser glitches on compromised websites. Source: https://www.bleepingcomputer.com/news/security/new-errtraffic-service-enables-clickfix-attacks-via-fake-browser-glitches/
  • ClickFix attacks abuse Windows App-V signed scripts with fake CAPTCHA to deliver Amatera infostealer. Source: https://www.bleepingcomputer.com/news/security/new-clickfix-attacks-abuse-windows-app-v-scripts-to-push-malware/
  • Microsoft documents ClickFix variant using nslookup DNS queries to retrieve PowerShell payload — first DNS-based ClickFix delivery. Deploys ModeloRAT. Source: https://www.bleepingcomputer.com/news/security/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/
  • QuickLens Chrome extension compromised to deliver ClickFix attacks — fake Google Update prompts, cryptocurrency theft, AMOS infostealer. 7,000 users affected. Source: https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/
  • Threadlinqs Intelligence publishes comprehensive analysis of Tesseract OCR typosquat campaign, contextualizing within broader ClickFix evolution timeline.
  • NCSC UK Weekly Threat Report documents Tesseract OCR typosquatting campaign using ClickFix — fake OCR tool sites target developers with multi-stage malware and heavy obfuscation.
  • As of 2026-05-29, this Tesseract OCR typosquat ClickFix campaign remains active but is superseded by its direct successor "OCRFix" (CYJAX, 2026-02-25), which adds EtherHiding blockchain C2 and ChatGPT-poisoning to recommend the fake site, with infrastructure (oklefe[.]com) still live. No CVE applies; the broader ClickFix ecosystem is escalating (ACSC Vidar advisory May 7, 700+ hijacked sites, server-side polymorphism).

Sources cited for Tesseract OCR Typosquat Campaign

Detection coverage for TL-2026-0162

As of 2026-03-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0162 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats