UNC5142
UNC5142 is a financially motivated threat actor associated with the CLEARFAKE/ClearFake activity cluster and the CLEARSHORT multistage JavaScript downloader framework. The group compromises vulnerable WordPress websites and injects malicious JavaScript into plugin files, theme files, or WordPress databases to distribute information-stealing malware to site visitors. Reported payloads include Atomic (AMOS), Lumma, Rhadamanthys (RADTHIEF), and Vidar, targeting both Windows and Apple macOS systems. UNC5142 is notable for using EtherHiding, leveraging smart contracts on the BNB Smart Chain as resilient command-and-control or payload-delivery infrastructure. CLEARSHORT communicates with blockchain-hosted smart-contract data to retrieve next-stage payloads, and reporting describes the group evolving from a single-contract design to a three-contract architecture resembling a proxy pattern to enable rapid updates and infrastructure rotation. The campaign has also used decentralized storage methods, legitimate Web3 libraries, and encrypted payload delivery. The actor uses social-engineering lures on compromised sites, including fake Google Chrome update prompts and ClickFix-style prompts that trick users into executing malicious commands. Landing pages have been hosted on Cloudflare pages.dev, and Windows infection chains have used HTA and PowerShell stages, while macOS chains have used bash-based retrieval of Atomic Stealer. Google Threat Intelligence Group tracked approximately 14,000 injected web pages and around 6,000 compromised WordPress sites associated with UNC5142/ClearFake activity by mid-2025. Reporting states the group has operated since at least 2023 and that no UNC5142 activity was observed after July 23, 2025, possibly indicating a pause or retooling. Known alias directly mentioned in the content: ClearFake / CLEARFAKE.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.
Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.
UNC5142 is conducting financially motivated campaigns distributing information-stealing malware using blockchain-based infrastructure (EtherHiding) to evade takedown and detection. They use a three-tier smart contract architecture on BNB Smart Chain to dynamically update payloads and manage C2 logic.
UNC5142 is a newly identified threat group leveraging EtherHiding, a technique for hiding malware on blockchains, to distribute malicious payloads.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.