UNC5142 is a financially motivated cybercriminal threat cluster associated with the ClearFake/CLEARSHORT ecosystem and the early operationalization of the EtherHiding technique for malware delivery. The actor is known for compromising vulnerable WordPress websites at scale and injecting malicious JavaScript into plugins, themes, or site databases to deliver multi-stage payloads to site visitors. Its infrastructure uses smart contracts on BNB Smart Chain as a resilient control layer, allowing the actor to rotate payload locations and delivery logic with minimal cost and without re-compromising already injected sites. Reporting has described an evolution from earlier ClearFake activity to CLEARSHORT, including a multi-contract architecture resembling a proxy pattern to support rapid updates and improved resilience. UNC5142 primarily distributes information-stealing malware, including Lumma, Vidar, Rhadamanthys, and Atomic macOS Stealer, and has targeted both Windows and macOS users. Delivery commonly relies on fake browser update prompts, fake verification pages, and ClickFix-style social engineering that tricks victims into executing malicious commands. The actor has also used compromised websites as staging points for JavaScript downloaders that retrieve encrypted or compressed next-stage content from blockchain-backed infrastructure, often through public RPC services and legitimate Web3 libraries. This approach complicates traditional domain- and IP-based disruption because the malicious logic is anchored in decentralized, globally accessible blockchain infrastructure. The cluster has been linked to large-scale website compromise activity, with approximately 14,000 injected web pages and thousands of compromised WordPress sites identified by mid-2025. UNC5142 appears to compromise vulnerable WordPress sites opportunistically rather than selecting victims by geography. Its operations show sustained iteration in obfuscation, encryption, and delivery tradecraft, including stronger payload protection and parallel infrastructure for resilience and testing. No high-confidence evidence in the supplied material supports attribution to a nation state; the dominant assessment is that UNC5142 is a financially motivated cybercriminal actor focused on credential and information theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the tracked framework/ecosystem associated with ClickFix and EtherHiding activity, but the article explicitly says the observed infrastructure does not match published UNC5142 indicators and stops short of attributing the activity directly to this group.
A criminal cluster using BNB Smart Chain infrastructure and compromised WordPress sites to distribute infostealers, often with ClickFix lures.
Activity cluster associated with ClickFix/ClearFake-style web injection and delivery infrastructure, including use of blockchain-based C2 resolution ("EtherHiding") and large-scale compromised WordPress distribution. In this content it is referenced as a related/overlapping infrastructure pattern rather than being definitively attributed to the OCRFix botnet operator.
Financially motivated activity cluster associated with large-scale compromise of WordPress sites and use of blockchain smart contracts (BNB Smart Chain) as resilient C2/next-stage payload retrieval ("EtherHiding"), used to distribute infostealers across Windows and macOS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.