Threat reportMalwareTL-2026-0162
Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites with PowerShell Payload Chaining and Defense Evasion
Tesseract OCR Typosquat Campaign (TL-2026-0162), also tracked as Tesseract OCR ClickFix, is a high-severity malware campaign, first published 2026-03-01. It has no confirmed attribution, affects Tesseract OCR Project Tesseract OCR (impersonated), maps to 24 MITRE ATT&CK techniques (T1005, T1027, T1027.010), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0162
- Threat ID
- TL-2026-0162
- Also known as
- Tesseract OCR ClickFix, Tesseract Typosquat Campaign
- Severity
- HIGH
- Status
- SUPERSEDED
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, research, education, financial
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How Tesseract OCR Typosquat Campaign works
A targeted phishing campaign impersonates the legitimate Tesseract OCR open-source project (60K+ GitHub stars) through typosquatted domains, using ClickFix-style social engineering to trick developers into executing PowerShell commands that deploy multi-stage malware. The campaign features heavy obfuscation, anti-analysis techniques, clipboard hijacking for payload delivery, and multiple defense evasion mechanisms including AMSI bypass, ETW patching, and environment fingerprinting.
A sophisticated malware campaign targets developers and power users searching for Tesseract OCR — the widely-used open-source Optical Character Recognition engine originally developed by HP Labs and later maintained by Google, with over 60,000 GitHub stars and millions of downloads. The campaign uses typosquatted domains that closely mimic the legitimate tesseract-ocr.github.io documentation site and official download pages.
**Attack Chain Overview**: Victims searching for Tesseract OCR downloads, documentation, or Windows installers are redirected to convincing typosquatted sites. These sites present a ClickFix-style interaction — a fake error dialog, CAPTCHA verification, or "system check" that instructs the user to open the Windows Run dialog (Win+R) and paste a command that has been silently copied to their clipboard. The clipboard payload is a PowerShell one-liner that initiates a multi-stage malware delivery chain.
**ClickFix Social Engineering Evolution**: This campaign represents an evolution of the ClickFix technique (first documented in 2024), which has rapidly become one of the most prevalent social engineering methods. Unlike earlier ClickFix campaigns that used generic "browser update" or "verification" pretexts, this variant specifically targets the developer community by impersonating a legitimate open-source tool. The ClickFix approach bypasses traditional email-based phishing defenses because the victim voluntarily executes the payload — no exploit, no attachment, no macro.
**Multi-Stage Payload Delivery**: - **Stage 1 (Clipboard + Run Dialog)**: PowerShell one-liner copied to clipboard via JavaScript. Uses window.navigator.clipboard.writeText() or document.execCommand('copy') to silently stage the payload. The command uses -ExecutionPolicy Bypass -WindowStyle Hidden to execute silently. - **Stage 2 (Downloader)**: The initial PowerShell downloads an obfuscated script from attacker infrastructure. The script uses Base64 encoding layered with XOR obfuscation and string concatenation to evade static detection. - **Stage 3 (Environment Check)**: Before deploying the final payload, the malware performs environment fingerprinting — checking for virtual machines (VMware, VirtualBox, Hyper-V via WMI queries), sandbox environments (checking for common analysis tools like Wireshark, Process Monitor, IDA Pro), and security products. It also checks the number of running processes, installed software count, and system uptime to detect automated analysis. - **Stage 4 (Defense Evasion)**: The malware implements AMSI bypass (patching AmsiScanBuffer in amsi.dll), ETW patching (disabling Event Tracing for Windows to blind EDR), and Windows Defender exclusion path addition via PowerShell (Add-MpPreference -ExclusionPath). - **Stage 5 (Final Payload)**: Deploys an information stealer targeting browser credentials, cryptocurrency wallets, SSH keys, and developer tokens (GitHub, GitLab, npm, PyPI API tokens). Also establishes persistence via scheduled tasks and startup folder shortcuts.
**Typosquatting Domains**: The campaign registers domains that closely resemble legitimate Tesseract OCR infrastructure: - tesseract-ocr[.]org (vs. legitimate tesseract-ocr.github.io) - tesseractocr[.]download - tesseract-download[.]com - tesseract-ocr-installer[.]com - ocr-tesseract[.]com These domains use valid HTTPS certificates (Let's Encrypt), professional-looking landing pages cloned from the real site, and SEO poisoning to appear in search results.
**Developer-Specific Targeting**: Unlike generic ClickFix campaigns, this variant specifically targets the developer ecosystem. Tesseract OCR is used extensively in document processing pipelines, data extraction workflows, and CI/CD systems. Compromising developer machines provides access to source code repositories, cloud credentials, API tokens, and CI/CD pipeline secrets.
**Obfuscation Techniques**: The PowerShell payloads use multiple layers of obfuscation: (1) Base64 encoding with -EncodedCommand, (2) String concatenation and variable substitution ('I'+'EX'), (3) Character code conversion ([char]73+[char]69+[char]88), (4) Environment variable abuse ($env:comspec), (5) Invoke-Expression aliasing via Set-Alias. Each stage is independently obfuscated with different techniques to defeat signature-based detection.
**Relationship to Prior ClickFix Campaigns**: This campaign shares infrastructure patterns with earlier ClickFix operations documented in TL-2026-0118, TL-2026-0120, and TL-2026-0127 (browser cache smuggling). The evolution from generic "browser update" pretexts to targeted developer tool impersonation represents a significant tactical advancement in the ClickFix ecosystem.
**Impact Assessment**: Developers who execute the payload face compromise of their entire development environment — source code, credentials, API tokens, SSH keys, and potentially CI/CD pipeline access. For enterprise developers, this can lead to supply chain compromise if attacker gains access to package registries or build systems.
MITRE ATT&CK techniques used in TL-2026-0162
collection
T1005 Data from Local System; T1115 Clipboard Data
stealth
T1027 Obfuscated Files or Information; T1027.010 Command Obfuscation; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1204.001 Malicious Link; T1204.002 Malicious File
discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
initial-access
T1189 Drive-by Compromise; T1566.002 Spearphishing Link
persistence
T1547.001 Registry Run Keys / Startup Folder
credential-access
T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers
resource-development
T1583.001 Domains; T1608.006 SEO Poisoning
defense-impairment
T1685 Disable or Modify Tools; T1685.001 Disable or Modify Windows Event Log
Affected products and versions in Tesseract OCR Typosquat Campaign
- Tesseract OCR Project — Tesseract OCR (impersonated)
Vulnerable versions: All — typosquatted download sites target any user searching for Tesseract
Fixed in: Official: github.com/tesseract-ocr/tesseract - Microsoft — Windows
Vulnerable versions: 10; 11; Server 2016+ - Multiple — Developer Workstations
Vulnerable versions: Any developer downloading OCR tools from search results
Remediation for Tesseract OCR Typosquat Campaign
Immediate actions
- Block known typosquatted Tesseract OCR domains at DNS/proxy level
- Alert developers to only download Tesseract OCR from github.com/tesseract-ocr/tesseract
- Hunt for PowerShell -ExecutionPolicy Bypass -WindowStyle Hidden executions on developer workstations
- Check clipboard history tools for suspicious PowerShell payloads
- Scan for AMSI bypass indicators (AmsiScanBuffer patching)
- Monitor for Add-MpPreference -ExclusionPath commands
- Review scheduled tasks and startup folder for recently added persistence
Workarounds
- Disable clipboard access from JavaScript in browser security settings
- Block PowerShell -EncodedCommand via AppLocker or WDAC policies
- Restrict Win+R Run dialog via Group Policy where appropriate
Longer-term hardening
- Implement application whitelisting on developer workstations
- Deploy PowerShell Constrained Language Mode where possible
- Enable enhanced PowerShell Script Block Logging (Event ID 4104)
- Implement DNS filtering with typosquat detection capability
- Deploy browser extensions that warn on known-bad domains
- Educate developers on ClickFix social engineering techniques
- Monitor for credential access to package registry tokens (npm, PyPI, GitHub)
Weaknesses (CWE) in Tesseract OCR Typosquat Campaign
Timeline of Tesseract OCR Typosquat Campaign
- ClickFix social engineering technique first documented — trick users into executing PowerShell/shell commands via fake error dialogs, CAPTCHAs, or update prompts.
- ConsentFix variant discovered — abuses Azure CLI OAuth app to hijack Microsoft accounts without passwords. Source: https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/
- ErrTraffic ClickFix-as-a-Service platform discovered — automates ClickFix attacks via fake browser glitches on compromised websites. Source: https://www.bleepingcomputer.com/news/security/new-errtraffic-service-enables-clickfix-attacks-via-fake-browser-glitches/
- ClickFix attacks abuse Windows App-V signed scripts with fake CAPTCHA to deliver Amatera infostealer. Source: https://www.bleepingcomputer.com/news/security/new-clickfix-attacks-abuse-windows-app-v-scripts-to-push-malware/
- Microsoft documents ClickFix variant using nslookup DNS queries to retrieve PowerShell payload — first DNS-based ClickFix delivery. Deploys ModeloRAT. Source: https://www.bleepingcomputer.com/news/security/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/
- QuickLens Chrome extension compromised to deliver ClickFix attacks — fake Google Update prompts, cryptocurrency theft, AMOS infostealer. 7,000 users affected. Source: https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/
- Threadlinqs Intelligence publishes comprehensive analysis of Tesseract OCR typosquat campaign, contextualizing within broader ClickFix evolution timeline.
- NCSC UK Weekly Threat Report documents Tesseract OCR typosquatting campaign using ClickFix — fake OCR tool sites target developers with multi-stage malware and heavy obfuscation.
- As of 2026-05-29, this Tesseract OCR typosquat ClickFix campaign remains active but is superseded by its direct successor "OCRFix" (CYJAX, 2026-02-25), which adds EtherHiding blockchain C2 and ChatGPT-poisoning to recommend the fake site, with infrastructure (oklefe[.]com) still live. No CVE applies; the broader ClickFix ecosystem is escalating (ACSC Vidar advisory May 7, 700+ hijacked sites, server-side polymorphism).
Sources cited for Tesseract OCR Typosquat Campaign
- NCSC Weekly Threat Report — Tesseract OCR Typosquatting / ClickFix Campaign
- BleepingComputer — New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS
- BleepingComputer — QuickLens Chrome extension steals crypto, shows ClickFix attack
- BleepingComputer — Claude LLM artifacts abused to push Mac infostealers in ClickFix attack
- BleepingComputer — New ClickFix attacks abuse Windows App-V scripts to push malware
- BleepingComputer — New ConsentFix attack hijacks Microsoft accounts via Azure CLI
- BleepingComputer — Fake ad blocker extension crashes browser for ClickFix attacks
- Tesseract OCR Official Repository — github.com/tesseract-ocr/tesseract
- BleepingComputer — ClickFix attack uses fake Windows BSOD screens to push malware
- BleepingComputer — ErrTraffic service enables ClickFix attacks via fake browser glitches
Detection coverage for TL-2026-0162
As of 2026-03-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0162 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.