UNC5142 is a financially motivated threat actor, also associated with the ClearFake cluster, that compromises vulnerable WordPress websites to distribute information-stealing malware. Reported malware delivered by this actor includes Lumma/LUMMAC.V2, Vidar, Rhadamanthys (RADTHIEF), and Atomic (AMOS), targeting both Windows and macOS users. UNC5142 is notable for using EtherHiding: blockchain smart contracts on the BNB Smart Chain as resilient malware delivery and control infrastructure. Multiple reports describe the actor injecting malicious JavaScript into WordPress plugin files, theme files, or databases, then using multistage JavaScript downloaders referred to as ClearFake and CLEARSHORT to retrieve next-stage payloads from BNB Smart Chain smart contracts. The infrastructure evolved from a single-contract design to a three-contract architecture resembling a proxy pattern, enabling rapid updates to payload locations and related components without reinfecting sites. The actor has used social-engineering lures including fake Google Chrome update prompts, fake Cloudflare verification, and ClickFix-style prompts that trick victims into executing malicious commands. Landing pages have been hosted on Cloudflare pages.dev, and payload delivery has also involved services such as GitHub and MediaFire. Google Threat Intelligence Group reporting cited approximately 14,000 injected web pages and around 6,000 compromised WordPress sites associated with UNC5142 activity, and separately noted roughly 14,000 compromised pages as of June 2025. Content also states Google had not observed UNC5142 activity after July 23, 2025, possibly indicating a pause or retooling. Known aliases and related naming in the provided content include ClearFake and CLEARSHORT as campaign/framework names associated with UNC5142.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A criminal cluster using BNB Smart Chain infrastructure and compromised WordPress sites to distribute infostealers, often with ClickFix lures.
Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.
Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.
UNC5142 is conducting financially motivated campaigns distributing information-stealing malware using blockchain-based infrastructure (EtherHiding) to evade takedown and detection. They use a three-tier smart contract architecture on BNB Smart Chain to dynamically update payloads and manage C2 logic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.