LummaC2 (referred to in the source content as LUMMAC.V2 / Lummac.V2) is an infostealer malware family distributed in campaigns attributed in the provided content to UNC5142, also described as the ClearFake cluster. In the cited activity, UNC5142 compromised WordPress sites, injected JavaScript downloaders known as ClearShort, and used BNB Smart Chain smart contracts as a control layer in an EtherHiding-style delivery chain. The operation also hosted malicious pages on Cloudflare pages.dev and used social-engineering lures including fake Cloudflare verification prompts and fake Chrome update prompts. The content states that these lures delivered infostealers including LummaC2, Vidar, and RadThief. High-confidence details in the provided material identify LummaC2 specifically as an infostealer; no additional family-specific capabilities beyond credential/data theft are directly described for LummaC2 itself in the source. The broader campaign infrastructure was described as resilient and rapidly updateable through blockchain-backed smart contracts, with UNC5142 maintaining parallel infrastructures and using low-cost blockchain transactions to update lure URLs or encryption keys across many infected sites.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5142 (ClearFake Cluster): Primarily uses the BNB Smart Chain to distribute infostealers such as LUMMAC.V2 and Vidar via compromised WordPress sites.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Traditionally, defenders could disrupt attacks by seizing domains or sinkholing IP addresses; however, the integration of blockchain technology renders these methods largely obsolete. By leveraging public ledgers, threat actors have created a resilient C2 layer... | Malware families, such as EtherRAT, function by querying public Remote Procedure Call (RPC) endpoints to read state data from specific smart contracts. This allows them to resolve the latest active C2 server addresses dynamically.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer distributed via compromised WordPress sites using blockchain-enabled delivery infrastructure.
Infostealer malware distributed by UNC5142 via blockchain-based infrastructure, targeting credentials and sensitive data.
Infostealer malware distributed by UNC5142 via blockchain-based infrastructure, targeting credentials and sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.