UNC5142 is a financially motivated cybercriminal threat cluster associated with the ClearFake malware-distribution campaign. Active since at least 2023, it compromises vulnerable WordPress websites and injects malicious JavaScript into plugins, themes, and databases to infect visitors with information-stealing malware. Its payloads include Atomic macOS Stealer (AMOS), Lumma, Rhadamanthys, and Vidar, targeting both Windows and macOS. Approximately 14,000 web pages contained JavaScript consistent with UNC5142 compromises by June 2025. Website targeting is indiscriminate rather than focused on a documented country or industry. The cluster uses fake browser-update notices, browser-error messages, and CAPTCHA or verification prompts. Its delivery framework evolved from ClearFake into the multistage JavaScript downloader CLEARSHORT. ClickFix lures persuade visitors to execute malicious commands through the Windows Run dialog or a macOS shell, initiating subsequent download and execution stages. Legitimate cloud-hosting and file-distribution services support parts of the delivery chain. UNC5142 is an early large-scale adopter of EtherHiding, using BNB Smart Chain smart contracts to provide malicious delivery content and infrastructure configuration. CLEARSHORT retrieves blockchain-hosted data through public blockchain interfaces and legitimate Web3 libraries. The infrastructure evolved from a single contract to a three-contract proxy architecture, allowing delivery components to be updated without replacing injected JavaScript on compromised websites. Victim profiling supports tailored payload delivery, while encryption, compression, and obfuscation complicate analysis. Blockchain-backed configuration and replaceable delivery infrastructure increase resilience against conventional hosting takedowns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EtherHiding activity cluster that compromised WordPress pages and used BNB Smart Chain contract storage to distribute the CLEARSHORT JavaScript downloader. It is historical context and is not linked to HexMage in this reference.
Operates the ClearFake campaign, using EtherHiding—blockchain smart contracts and legitimate blockchain-infrastructure services—to resiliently deliver or redirect victims to malicious content and C2 infrastructure.
Referenced as the tracked framework/ecosystem associated with ClickFix and EtherHiding activity, but the article explicitly says the observed infrastructure does not match published UNC5142 indicators and stops short of attributing the activity directly to this group.
A financially motivated activity cluster tracked by GTIG in connection with ClickFix-driven malware delivery and EtherHiding, using blockchain-based dead drops for next-stage resolution. The analyzed intrusion resembles this shared ecosystem but is not attributed conclusively to UNC5142.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.