CLEARSHORT is a multistage JavaScript downloader associated with the financially motivated threat cluster UNC5142 and the broader ClearFake/ClickFix/EtherHiding ecosystem. It is used primarily on compromised WordPress sites, where injected JavaScript acts as a delivery bridge between a victim’s browser and attacker-controlled payload infrastructure hosted through smart contracts on the BNB Smart Chain. The framework evolved from earlier fake browser-update activity linked to ClearFake and adopted ClickFix-style social engineering to induce victims to execute malicious commands, particularly on Windows systems through the Run dialog and on macOS through terminal-based prompts.
A defining characteristic of CLEARSHORT is its use of public blockchain infrastructure as a resilient control layer. It retrieves staged content from smart contracts using legitimate Web3 tooling, with retrieved data encoded, compressed, and in later iterations encrypted before browser-side decryption and execution. Reported architectures include a multi-contract design resembling a proxy pattern, allowing operators to rotate payload locations, encryption material, and lure infrastructure without reinfecting already compromised websites. This design materially increases resilience against takedown and infrastructure disruption.
CLEARSHORT has been used to deliver follow-on malware including information stealers such as Atomic for macOS, Lumma, Rhadamanthys, and Vidar. In observed Windows infection chains, ClickFix lures led to PowerShell execution, staged download of additional components, deployment of Python runtimes, persistence creation, host reconnaissance, blockchain-based dead-drop resolution, and subsequent loader activity consistent with process injection and attempted privilege escalation. The malware ecosystem around CLEARSHORT therefore supports initial access, payload retrieval, defense evasion through obfuscation and in-memory staging, and post-compromise delivery of credential- and data-theft tooling.
The activity has targeted visitors to compromised websites at scale, with thousands of injected pages observed. Targeting has included both Windows and macOS users, with delivery tailored to the victim platform. CLEARSHORT is best understood as a downloader framework and delivery mechanism rather than the final theft payload itself, enabling UNC5142 to distribute commodity infostealers through decentralized, difficult-to-disrupt infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The technique stack points at the ClickFix and EtherHiding malware-as-a-service ecosystem that grew out of CLEARFAKE and CLEARSHORT...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of the broader ecosystem associated with EtherHiding-style delivery; noted as a JavaScript first stage in canonical UNC5142 activity.
CLEARSHORT is a multistage JavaScript downloader used by UNC5142 to retrieve and execute malicious payloads from blockchain-based infrastructure. It leverages a three-tier smart contract architecture on the BNB Smart Chain to dynamically fetch, decrypt, and execute payloads in the victim's browser, evading traditional C2 takedown methods.
Evolved CLEARFAKE variant used on compromised WordPress sites; leverages Web3.js to interact with BNB Smart Chain via a public node and retrieve payload components from smart contracts (including via an upgradable proxy-pattern contract architecture).
JavaScript downloader injected into compromised WordPress sites, using blockchain smart contracts for command and control. Used by UNC5142 to distribute infostealers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.