UNC5142
UNC5142 is a financially motivated threat actor that has used the EtherHiding technique since 2023 to distribute information-stealing malware. The group compromises vulnerable WordPress websites and injects malicious JavaScript into plugin files, theme files, or WordPress databases, using those sites to deliver malware to visitors. Google tracked approximately 14,000 injected web pages and about 6,000 compromised WordPress sites associated with this activity, and reported no observed UNC5142 activity after July 23, 2025. UNC5142 is associated with the JavaScript frameworks CLEARSHORT and ClearFake. CLEARSHORT is described as a multistage JavaScript downloader that bridges compromised browsers with blockchain infrastructure. The group uses BNB Smart Chain smart contracts as a control layer to retrieve next-stage payloads, and evolved from a single-contract design to a three-smart-contract architecture resembling a proxy pattern, enabling rapid updates to payload URLs, lures, and encryption without changing the injected site code. Reported supporting infrastructure includes Cloudflare pages.dev landing pages and public blockchain/RPC access. The actor uses social-engineering lures including fake Google Chrome update pop-ups, fake Cloudflare verification, and ClickFix-style prompts that trick users into executing malicious commands. On Windows, reported delivery has included HTA and PowerShell-based chains fetching payloads from GitHub, MediaFire, or attacker infrastructure. On macOS, ClickFix decoys have been used to deliver Atomic Stealer. Malware families attributed in the content to UNC5142 include Atomic (AMOS), Lumma, Vidar, and Rhadamanthys/RADTHIEF, targeting both Windows and Apple macOS systems. The group is described as operating at high tempo, maintaining parallel Main and Secondary smart-contract infrastructures, and using blockchain-based delivery to improve resiliency against takedown and detection.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- technology
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.
Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.
UNC5142 is conducting financially motivated campaigns distributing information-stealing malware using blockchain-based infrastructure (EtherHiding) to evade takedown and detection. They use a three-tier smart contract architecture on BNB Smart Chain to dynamically update payloads and manage C2 logic.
UNC5142 is a newly identified threat group leveraging EtherHiding, a technique for hiding malware on blockchains, to distribute malicious payloads.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.