CLEARSHORT is a multistage JavaScript downloader used by the financially motivated UNC5142 threat actor in EtherHiding campaigns. It is injected into compromised WordPress websites, including plugin, theme, and database content, and uses BNB Smart Chain smart contracts as a resilient control layer to retrieve staged malicious content. CLEARSHORT uses Web3 functionality and legitimate JavaScript libraries to query blockchain infrastructure, then decodes, decompresses, and decrypts returned data before executing or directing victims to subsequent payloads. UNC5142 evolved the associated smart-contract infrastructure from a single contract to a multi-contract, proxy-like architecture that permits payload locations, lures, and encryption material to be updated without reinfecting websites. Infection chains commonly use fake browser-update, verification, and ClickFix lures that persuade victims to execute commands. CLEARSHORT has been used to distribute information stealers including Atomic Stealer, Lumma, Rhadamanthys, and Vidar against Windows and macOS users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Google Threat Intelligence Group and Mandiant documented UNC5142 using EtherHiding at scale on BNB Smart Chain and delivering a JavaScript downloader tracked as CLEARSHORT.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JavaScript downloader used in UNC5142 EtherHiding activity against compromised WordPress pages. It is included only as historical context and is not attributed to the HexMage card-skimming cluster.
Uses BNB Smart Chain contracts as a dead drop resolver to retrieve obfuscated JavaScript or bash stagers.
Referenced as part of the broader ecosystem associated with EtherHiding-style delivery; noted as a JavaScript first stage in canonical UNC5142 activity.
CLEARSHORT is a multistage JavaScript downloader used by UNC5142 to retrieve and execute malicious payloads from blockchain-based infrastructure. It leverages a three-tier smart contract architecture on the BNB Smart Chain to dynamically fetch, decrypt, and execute payloads in the victim's browser, evading traditional C2 takedown methods.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.