# Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites with PowerShell Payload Chaining and Defense Evasion

> A targeted phishing campaign impersonates the legitimate Tesseract OCR open-source project (60K+ GitHub stars) through typosquatted domains, using ClickFix-style social engineering to trick developers into executing PowerShell commands that deploy multi-stage malware. The campaign features heavy obfuscation, anti-analysis techniques, clipboard hijacking for payload delivery, and multiple defense evasion mechanisms including AMSI bypass, ETW patching, and environment fingerprinting.

- **Published:** 2026-03-01T09:57:59Z
- **Last reviewed:** 2026-03-01T09:57:59Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0162
- **ID:** TL-2026-0162
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** SUPERSEDED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A sophisticated malware campaign targets developers and power users searching for Tesseract OCR — the widely-used open-source Optical Character Recognition engine originally developed by HP Labs and later maintained by Google, with over 60,000 GitHub stars and millions of downloads. The campaign uses typosquatted domains that closely mimic the legitimate tesseract-ocr.github.io documentation site and official download pages.

**Attack Chain Overview**: Victims searching for Tesseract OCR downloads, documentation, or Windows installers are redirected to convincing typosquatted sites. These sites present a ClickFix-style interaction — a fake error dialog, CAPTCHA verification, or "system check" that instructs the user to open the Windows Run dialog (Win+R) and paste a command that has been silently copied to their clipboard. The clipboard payload is a PowerShell one-liner that initiates a multi-stage malware delivery chain.

**ClickFix Social Engineering Evolution**: This campaign represents an evolution of the ClickFix technique (first documented in 2024), which has rapidly become one of the most prevalent social engineering methods. Unlike earlier ClickFix campaigns that used generic "browser update" or "verification" pretexts, this variant specifically targets the developer community by impersonating a legitimate open-source tool. The ClickFix approach bypasses traditional email-based phishing defenses because the victim voluntarily executes the payload — no exploit, no attachment, no macro.

**Multi-Stage Payload Delivery**:
- **Stage 1 (Clipboard + Run Dialog)**: PowerShell one-liner copied to clipboard via JavaScript. Uses window.navigator.clipboard.writeText() or document.execCommand('copy') to silently stage the payload. The command uses -ExecutionPolicy Bypass -WindowStyle Hidden to execute silently.
- **Stage 2 (Downloader)**: The initial PowerShell downloads an obfuscated script from attacker infrastructure. The script uses Base64 encoding layered with XOR obfuscation and string concatenation to evade static detection.
- **Stage 3 (Environment Check)**: Before deploying the final payload, the malware performs environment fingerprinting — checking for virtual machines (VMware, VirtualBox, Hyper-V via WMI queries), sandbox environments (checking for common analysis tools like Wireshark, Process Monitor, IDA Pro), and security products. It also checks the number of running processes, installed software count, and system uptime to detect automated analysis.
- **Stage 4 (Defense Evasion)**: The malware implements AMSI bypass (patching AmsiScanBuffer in amsi.dll), ETW patching (disabling Event Tracing for Windows to blind EDR), and Windows Defender exclusion path addition via PowerShell (Add-MpPreference -ExclusionPath).
- **Stage 5 (Final Payload)**: Deploys an information stealer targeting browser credentials, cryptocurrency wallets, SSH keys, and developer tokens (GitHub, GitLab, npm, PyPI API tokens). Also establishes persistence via scheduled tasks and startup folder shortcuts.

**Typosquatting Domains**: The campaign registers domains that closely resemble legitimate Tesseract OCR infrastructure:
- tesseract-ocr[.]org (vs. legitimate tesseract-ocr.github.io)
- tesseractocr[.]download
- tesseract-download[.]com
- tesseract-ocr-installer[.]com
- ocr-tesseract[.]com
These domains use valid HTTPS certificates (Let's Encrypt), professional-looking landing pages cloned from the real site, and SEO poisoning to appear in search results.

**Developer-Specific Targeting**: Unlike generic ClickFix campaigns, this variant specifically targets the developer ecosystem. Tesseract OCR is used extensively in document processing pipelines, data extraction workflows, and CI/CD systems. Compromising developer machines provides access to source code repositories, cloud credentials, API tokens, and CI/CD pipeline secrets.

**Obfuscation Techniques**: The PowerShell payloads use multiple layers of obfuscation: (1) Base64 encoding with -EncodedCommand, (2) String concatenation and variable substitution ('I'+'EX'), (3) Character code conversion ([char]73+[char]69+[char]88), (4) Environment variable abuse ($env:comspec), (5) Invoke-Expression aliasing via Set-Alias. Each stage is independently obfuscated with different techniques to defeat signature-based detection.

**Relationship to Prior ClickFix Campaigns**: This campaign shares infrastructure patterns with earlier ClickFix operations documented in TL-2026-0118, TL-2026-0120, and TL-2026-0127 (browser cache smuggling). The evolution from generic "browser update" pretexts to targeted developer tool impersonation represents a significant tactical advancement in the ClickFix ecosystem.

**Impact Assessment**: Developers who execute the payload face compromise of their entire development environment — source code, credentials, API tokens, SSH keys, and potentially CI/CD pipeline access. For enterprise developers, this can lead to supply chain compromise if attacker gains access to package registries or build systems.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1189 Drive-by Compromise
- T1059.001 PowerShell
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1053.005 Scheduled Task
- T1547.001 Registry Run Keys / Startup Folder
- T1027 Obfuscated Files or Information
- T1027.010 Command Obfuscation
- T1140 Deobfuscate/Decode Files or Information
- T1685 Disable or Modify Tools
- T1685.001 Disable or Modify Windows Event Log
- T1497.001 System Checks
- T1036.005 Match Legitimate Resource Name or Location
- T1555.003 Credentials from Web Browsers
- T1552.001 Credentials In Files
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518.001 Security Software Discovery
- T1005 Data from Local System
- T1115 Clipboard Data
- T1041 Exfiltration Over C2 Channel
- T1583.001 Domains
- T1608.006 SEO Poisoning

## Sources

- [NCSC Weekly Threat Report — Tesseract OCR Typosquatting / ClickFix Campaign](https://www.ncsc.gov.uk/report/weekly-threat-report)
- [BleepingComputer — New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS](https://www.bleepingcomputer.com/news/security/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/)
- [BleepingComputer — QuickLens Chrome extension steals crypto, shows ClickFix attack](https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/)
- [BleepingComputer — Claude LLM artifacts abused to push Mac infostealers in ClickFix attack](https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/)
- [BleepingComputer — New ClickFix attacks abuse Windows App-V scripts to push malware](https://www.bleepingcomputer.com/news/security/new-clickfix-attacks-abuse-windows-app-v-scripts-to-push-malware/)
- [BleepingComputer — New ConsentFix attack hijacks Microsoft accounts via Azure CLI](https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/)
- [BleepingComputer — Fake ad blocker extension crashes browser for ClickFix attacks](https://www.bleepingcomputer.com/news/security/fake-ad-blocker-extension-crashes-the-browser-for-clickfix-attacks/)
- [Tesseract OCR Official Repository — github.com/tesseract-ocr/tesseract](https://github.com/tesseract-ocr/tesseract)
- [BleepingComputer — ClickFix attack uses fake Windows BSOD screens to push malware](https://www.bleepingcomputer.com/news/security/clickfix-attack-uses-fake-windows-bsod-screens-to-push-malware/)
- [BleepingComputer — ErrTraffic service enables ClickFix attacks via fake browser glitches](https://www.bleepingcomputer.com/news/security/new-errtraffic-service-enables-clickfix-attacks-via-fake-browser-glitches/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0162
