Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
6 malware families

UNC5142

Also known asunc5142

UNC5142 is a financially motivated threat actor associated with the CLEARFAKE/ClearFake activity cluster and the CLEARSHORT multistage JavaScript downloader framework. The group compromises vulnerable WordPress websites and injects malicious JavaScript into plugin files, theme files, or WordPress databases to distribute information-stealing malware to site visitors. Reported payloads include Atomic (AMOS), Lumma, Rhadamanthys (RADTHIEF), and Vidar, targeting both Windows and Apple macOS systems. UNC5142 is notable for using EtherHiding, leveraging smart contracts on the BNB Smart Chain as resilient command-and-control or payload-delivery infrastructure. CLEARSHORT communicates with blockchain-hosted smart-contract data to retrieve next-stage payloads, and reporting describes the group evolving from a single-contract design to a three-contract architecture resembling a proxy pattern to enable rapid updates and infrastructure rotation. The campaign has also used decentralized storage methods, legitimate Web3 libraries, and encrypted payload delivery. The actor uses social-engineering lures on compromised sites, including fake Google Chrome update prompts and ClickFix-style prompts that trick users into executing malicious commands. Landing pages have been hosted on Cloudflare pages.dev, and Windows infection chains have used HTA and PowerShell stages, while macOS chains have used bash-based retrieval of Atomic Stealer. Google Threat Intelligence Group tracked approximately 14,000 injected web pages and around 6,000 compromised WordPress sites associated with UNC5142/ClearFake activity by mid-2025. Reporting states the group has operated since at least 2023 and that no UNC5142 activity was observed after July 23, 2025, possibly indicating a pause or retooling. Known alias directly mentioned in the content: ClearFake / CLEARFAKE.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1189
Drive-by Compromise
T1566
Phishing
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
T1203
Exploitation for Client Execution
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1140
Deobfuscate/Decode Files or Information
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1102×2
Web Service
T1105
Ingress Tool Transfer
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

derp ca blogNews
Mar 3, 2026
OCRFix botnet hides C2 in BNB Smart Chain contracts | Derp

Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.

Read more
flareio blogNews
Feb 10, 2026
The macOS Stealer Gold Rush: How Cybercriminals Are Racing to Exploit Apple's ' Ecosystem - Flare | Threat Exposure Management | Unmatched Visibility into Cybercrime

Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.

Read more
picus security blogNews
Dec 4, 2025
EtherHiding: How Web3 Infrastructure Enables Stealthy Malware Distribution

UNC5142 is conducting financially motivated campaigns distributing information-stealing malware using blockchain-based infrastructure (EtherHiding) to evade takedown and detection. They use a three-tier smart contract architecture on BNB Smart Chain to dynamically update payloads and manage C2 logic.

Read more
securityaffairsNews
Oct 19, 2025
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 67

UNC5142 is a newly identified threat group leveraging EtherHiding, a technique for hiding malware on blockchains, to distribute malicious payloads.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.