UNC5142 is a financially motivated cybercriminal cluster associated with the ClearFake campaign and the CLEARSHORT multistage JavaScript downloader. Active from 2023, it compromises vulnerable WordPress websites and injects malicious JavaScript into site components and databases, exposing visitors to fake browser-update, verification, CAPTCHA, and ClickFix lures. The operation distributes information stealers including Atomic Stealer (AMOS), Lumma, Rhadamanthys, and Vidar against Windows and macOS users. UNC5142 pioneered large-scale use of EtherHiding, using BNB Smart Chain smart contracts as a resilient control and payload-delivery layer. CLEARSHORT queries blockchain contracts through public RPC services, retrieves further-stage content or configuration, and can decrypt and execute returned payloads in the browser. The actor evolved from a single-contract design to a multi-contract proxy architecture that separates routing, victim profiling and telemetry, and payload delivery. This design enables rapid changes to lures, payload locations, and encryption material without reinfecting already compromised websites. The group has been linked to more than 14,000 web pages containing its injected JavaScript as of mid-2025. Its infrastructure and delivery mechanisms emphasize evasion and operational resilience through public blockchain services, encrypted payload handling, JavaScript obfuscation, compromised legitimate websites, and social-engineering prompts that impersonate trusted browser or verification workflows.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EtherHiding activity cluster that compromised WordPress pages and used BNB Smart Chain contract storage to distribute the CLEARSHORT JavaScript downloader. It is historical context and is not linked to HexMage in this reference.
Operates the ClearFake campaign, using EtherHiding—blockchain smart contracts and legitimate blockchain-infrastructure services—to resiliently deliver or redirect victims to malicious content and C2 infrastructure.
Referenced as the tracked framework/ecosystem associated with ClickFix and EtherHiding activity, but the article explicitly says the observed infrastructure does not match published UNC5142 indicators and stops short of attributing the activity directly to this group.
A criminal cluster using BNB Smart Chain infrastructure and compromised WordPress sites to distribute infostealers, often with ClickFix lures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.