UNC5142 is a financially motivated cybercriminal threat cluster associated with the ClearFake and CLEARSHORT malware delivery ecosystem. The group is known for compromising vulnerable WordPress websites at scale and injecting malicious JavaScript that redirects site visitors into multi-stage malware infection chains. Its operations have primarily focused on distributing information stealers, including Lumma, Vidar, Rhadamanthys, and Atomic macOS Stealer, against both Windows and macOS users. A defining characteristic of UNC5142 is its use of blockchain-backed delivery and control infrastructure, particularly on BNB Smart Chain, in a technique widely referred to as EtherHiding. Rather than relying solely on conventional domains or static command-and-control infrastructure, UNC5142 uses smart contracts as a resilient control layer to deliver next-stage payload locations, configuration data, and related components. Reporting has described the group’s infrastructure evolving from simpler contract usage to a more modular multi-contract architecture resembling a proxy pattern, enabling rapid updates to payload delivery logic without reinfecting compromised websites. UNC5142’s web-based infection chains are commonly tied to the ClearFake cluster and its later CLEARSHORT framework. ClearFake historically used fake browser update prompts, especially Chrome-themed lures, while later activity incorporated ClickFix-style social engineering that tricks users into manually executing malicious commands through the Windows Run dialog or terminal-like prompts. The injected JavaScript has been observed in WordPress plugins, themes, and database content, and often retrieves additional stages from blockchain-referenced infrastructure. The group has also used cloud-hosted landing pages and encrypted or obfuscated JavaScript stages to complicate detection and takedown. The actor’s tradecraft emphasizes resilience, scalability, and low-cost infrastructure rotation. By abusing public blockchain smart contracts and public RPC or API services, UNC5142 can update malware delivery chains quickly and cheaply while reducing dependence on easily seized infrastructure. This approach complicates traditional domain- and IP-based disruption because the malicious logic is anchored in decentralized, immutable platforms, while the surrounding delivery chain can be changed frequently. UNC5142 has been linked to large-scale website compromise activity, with public reporting identifying roughly 14,000 injected web pages and thousands of compromised WordPress sites during the height of the campaign. The targeting appears largely opportunistic at the website-compromise stage, with downstream victimization affecting visitors to those sites rather than a narrowly defined vertical. The cluster is widely tracked in connection with ClearFake, CLEARSHORT, and EtherHiding-enabled malware distribution. No confirmed nation-state attribution is associated with UNC5142; it is consistently described as a financially motivated actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the tracked framework/ecosystem associated with ClickFix and EtherHiding activity, but the article explicitly says the observed infrastructure does not match published UNC5142 indicators and stops short of attributing the activity directly to this group.
A criminal cluster using BNB Smart Chain infrastructure and compromised WordPress sites to distribute infostealers, often with ClickFix lures.
Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.
Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.