Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-01

UNC5142

Also known as:ClearFake

As of 2026-08-26, UNC5142 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as ClearFake. ATT&CK coverage spans 50 techniques across 11 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel).

Tracked threats
22 high
First seen
2026-01-01
Last seen
2026-05-26
ATT&CK techniques
50across 2 of 2 threats
Related CVEs
0None referenced
2 tracked threat(s) · Categories: MALWARE

Activity timeline

UNC5142 appears in 2 tracked threats between and ; the busiest month was 2026-01 with 1 report.

ATT&CK techniques observed

50 techniques observed across 2 of 2 tracked threats · Stealth (formerly Defense Evasion) (16), Command and Control (7), Discovery (6), Execution (6), Resource Development (4), Credential Access (3)
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 2 tracked threats
  • T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 2 tracked threats
  • T1008 Fallback Channels — Command and Controlobserved in 1 of 2 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1016.001 Internet Connection Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1027.013 Encrypted/Encoded File — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1055.003 Thread Execution Hijacking — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats

Tracked threats