CLEARSHORT is a multistage JavaScript downloader used by the financially motivated UNC5142 threat actor in EtherHiding campaigns. It is injected into compromised WordPress websites, including plugin, theme, and database content, and uses BNB Smart Chain smart contracts as a resilient control and payload-delivery layer. Its contract architecture evolved from single-contract delivery to a multi-contract proxy-like design that permits operators to rotate landing pages, payload locations, encryption material, and other delivery components without reinfecting compromised sites.
CLEARSHORT uses legitimate Web3 and cryptographic libraries to retrieve encoded, compressed, and encrypted data from blockchain contracts, decrypt the recovered content in the browser, and execute subsequent malicious stages. It has been associated with fake browser-update, fake verification, and ClickFix lures that induce visitors to execute commands through the Windows Run dialog. UNC5142 has used the framework to distribute information stealers including Atomic Stealer, Lumma, Rhadamanthys, and Vidar. Campaigns have targeted both Windows and macOS users. Blockchain-based delivery and use of public RPC services increase resilience against conventional infrastructure takedowns and facilitate rapid updates to active infection chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The content contrasts the observed all-Python chain with canonical UNC5142 EtherHiding activity, which uses a JavaScript CLEARSHORT first stage on BNB Smart Chain.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JavaScript downloader used in UNC5142 EtherHiding activity against compromised WordPress pages. It is included only as historical context and is not attributed to the HexMage card-skimming cluster.
Uses BNB Smart Chain contracts as a dead drop resolver to retrieve obfuscated JavaScript or bash stagers.
Referenced as part of the broader ecosystem associated with EtherHiding-style delivery; noted as a JavaScript first stage in canonical UNC5142 activity.
A JavaScript first-stage malware/framework associated in the content with canonical UNC5142 EtherHiding activity; it is cited as a comparison rather than identified in the analyzed execution chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.