Skip to main content
Mallory
6 malware families

UNC5142

Also known asunc5142

UNC5142 is a financially motivated threat actor that has used the EtherHiding technique since 2023 to distribute information-stealing malware. The group compromises vulnerable WordPress websites and injects malicious JavaScript into plugin files, theme files, or WordPress databases, using those sites to deliver malware to visitors. Google tracked approximately 14,000 injected web pages and about 6,000 compromised WordPress sites associated with this activity, and reported no observed UNC5142 activity after July 23, 2025. UNC5142 is associated with the JavaScript frameworks CLEARSHORT and ClearFake. CLEARSHORT is described as a multistage JavaScript downloader that bridges compromised browsers with blockchain infrastructure. The group uses BNB Smart Chain smart contracts as a control layer to retrieve next-stage payloads, and evolved from a single-contract design to a three-smart-contract architecture resembling a proxy pattern, enabling rapid updates to payload URLs, lures, and encryption without changing the injected site code. Reported supporting infrastructure includes Cloudflare pages.dev landing pages and public blockchain/RPC access. The actor uses social-engineering lures including fake Google Chrome update pop-ups, fake Cloudflare verification, and ClickFix-style prompts that trick users into executing malicious commands. On Windows, reported delivery has included HTA and PowerShell-based chains fetching payloads from GitHub, MediaFire, or attacker infrastructure. On macOS, ClickFix decoys have been used to deliver Atomic Stealer. Malware families attributed in the content to UNC5142 include Atomic (AMOS), Lumma, Vidar, and Rhadamanthys/RADTHIEF, targeting both Windows and Apple macOS systems. The group is described as operating at high tempo, maintaining parallel Main and Secondary smart-contract infrastructures, and using blockchain-based delivery to improve resiliency against takedown and detection.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • technology
MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

3 of 15 tactics7 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1189
Drive-by Compromise
T1566
Phishing
TA0002
Execution
1 technique
T1203
Exploitation for Client Execution
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1102×2
Web Service
T1105
Ingress Tool Transfer
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

derp ca blogNews
Mar 3, 2026
OCRFix botnet hides C2 in BNB Smart Chain contracts | Derp

Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.

Read more
flareio blogNews
Feb 10, 2026
The macOS Stealer Gold Rush: How Cybercriminals Are Racing to Exploit Apple's ' Ecosystem - Flare | Threat Exposure Management | Unmatched Visibility into Cybercrime

Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.

Read more
picus security blogNews
Dec 4, 2025
EtherHiding: How Web3 Infrastructure Enables Stealthy Malware Distribution

UNC5142 is conducting financially motivated campaigns distributing information-stealing malware using blockchain-based infrastructure (EtherHiding) to evade takedown and detection. They use a three-tier smart contract architecture on BNB Smart Chain to dynamically update payloads and manage C2 logic.

Read more
securityaffairsNews
Oct 19, 2025
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 67

UNC5142 is a newly identified threat group leveraging EtherHiding, a technique for hiding malware on blockchains, to distribute malicious payloads.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.