Threat reportMalwareTL-2026-1512
UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Sites
UNC5142 EtherHiding (TL-2026-1512), also tracked as EtherHiding Campaign, is a high-severity malware campaign, first published 2026-01-01. It is attributed to UNC5142 with high confidence, affects WordPress WordPress core / plugins / themes (vulnerable/outdated, maps to 23 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 42 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1UNC5142
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 42Indicators of compromise
Key facts for TL-2026-1512
- Threat ID
- TL-2026-1512
- Also known as
- EtherHiding Campaign, CLEARSHORT
- Severity
- HIGH
- Status
- TRACKING
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UNC5142
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, ecommerce, general internet users, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 42
Malware and tooling in UNC5142 EtherHiding
Malware and tooling: ATOMIC, CLEARSHORT, LUMMAC.V2, RADTHIEF, Vidar, 0x53fd54f55C93f9BCCA471cD0CcbaBC3Acbd3E4AA, 0x8FBA1667BEF5EdA433928b220886A830488549BD, 0x9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53
How UNC5142 EtherHiding works
UNC5142, a financially motivated cluster tracked by Mandiant Threat Defense and Google Threat Intelligence Group since late 2023, abused a three-level BNB Smart Chain smart-contract system ("EtherHiding") to dynamically store and serve malicious CLEARSHORT JavaScript payload configurations across roughly 14,000 compromised WordPress sites, using evolving social-engineering ClickFix-style lures to deliver VIDAR, LUMMAC.V2 (Lumma), RADTHIEF (Rhadamanthys), and ATOMIC (AMOS) infostealers to Windows and macOS victims. No activity has been observed since July 23, 2025.
UNC5142 compromises WordPress sites running vulnerable core, plugin, or theme versions and injects a multistage JavaScript downloader family tracked as CLEARSHORT into theme files (header.php, footer.php, index.php), plugin directories, or the WordPress database. On page load, CLEARSHORT Stage 1 loads the Web3.js, pako (gzip), and crypto-js libraries and connects to the BNB Smart Chain via the public bsc-dataseed.binance.org RPC node to query a First-Level (router) smart contract, which returns a Base64/gzip-encoded ABI and the address of a Second-Level (logic) smart contract. The Second-Level contract exposes four functions used for victim fingerprinting and reconnaissance -- teaCeremony (dynamic code execution / POST check-ins), shibuyaCrossing (OS/platform identification), asakusaTemple (interaction beaconing), and ginzaLuxury (malicious lure retrieval/decryption) -- and its returned script is directly eval()'d in the victim browser. That script performs WebRTC/STUN-based IP address recovery (querying stun.l.google.com:19302 and POSTing the recovered IP to actor-controlled check-in domains such as saaadnesss[.]shop and lapkimeow[.]icu, later ratatui[.]today) and queries a Third-Level (storage) smart contract that holds an AES-GCM-encrypted CLEARSHORT landing page URL, the AES key, and second-stage payload URLs. The decrypted landing page presents an evolving series of ClickFix-style social-engineering lures -- fake Chrome update prompts, fake reCAPTCHA/Data Privacy dialogs, a spoofed Cloudflare "Unusual Web Traffic" error, and later an "Anti-Bot Verification" prompt for both Windows and macOS -- that trick the victim into executing an attacker-supplied command. This leads to a four-stage delivery chain: an initial dropper (.hta or a .xll file masquerading as an Excel add-in) fetched from Cloudflare Pages (*.pages.dev) or attacker infrastructure; a PowerShell loader (invoked with -ep RemoteSigned -w 1 -enc) that performs AES/TripleDES decryption and defense evasion (including ipconfig /flushdns and Mark-of-the-Web bypasses via xattr -c on macOS or NTFS Zone.Identifier stream removal on Windows); abuse of legitimate services (GitHub, MediaFire, Cloudflare Pages, and in early campaigns Backblaze B2) to host an encrypted payload blob disguised with benign extensions (.mp4, .mp3, .wav, .dat); and finally in-memory, no-disk-write execution of a .NET loader that decrypts and runs the final infostealer payload. UNC5142 operated two parallel smart-contract infrastructures -- a Main system deployed November 24, 2024 and a Secondary system deployed February 18, 2025 -- both funded from the same OKX exchange intermediary wallet and updated in near-lockstep (including a coordinated update on March 3, 2025), which GTIG assesses with high confidence indicates single-actor control. Updates to the on-chain configuration typically cost $0.25-$1.50 in BNB network fees, making the infrastructure extremely cheap to maintain and, because the blockchain component is immutable and publicly distributed, effectively resistant to conventional takedown. GTIG does not attribute the final infostealer payloads to UNC5142 directly and assesses the cluster most likely operates as a stolen-credential/data distribution service selling access to downstream threat actors. No CVE is associated with this campaign; initial access is achieved purely through vulnerable WordPress installations and social engineering rather than a specific software vulnerability. No UNC5142 activity has been observed since July 23, 2025, which GTIG assesses may represent an operational pause or a shift in tradecraft rather than the end of the cluster.
MITRE ATT&CK techniques used in TL-2026-1512
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools; T1568 Dynamic Resolution
Discovery
T1082 System Information Discovery; T1614 System Location Discovery
Initial Access
T1190 Exploit Public-Facing Application
stealth
T1216 System Script Proxy Execution; T1218.005 Mshta
Credential Access
T1539 Steal Web Session Cookie; T1552.001 Credentials In Files
defense-impairment
T1553.005 Mark-of-the-Web Bypass
Persistence
T1554 Compromise Host Software Binary
discovery
T1580 Cloud Infrastructure Discovery
Resource Development
Affected products and versions in UNC5142 EtherHiding
- WordPress — WordPress core / plugins / themes (vulnerable/outdated installations)
Vulnerable versions: Outdated or misconfigured WordPress core, plugin, and theme installations (no specific version enumerated by source)
Fixed in: Latest patched WordPress core, plugin, and theme versions - Multiple — Windows end-user endpoints (infostealer targets: VIDAR, LUMMAC.V2, RADTHIEF)
Vulnerable versions: Windows systems exposed to ClickFix-style social engineering - Apple — macOS end-user endpoints (infostealer target: ATOMIC/AMOS)
Vulnerable versions: macOS systems exposed to ClickFix-style social engineering
Remediation for UNC5142 EtherHiding
Patches
- Apply the latest official security patches/updates for the specific WordPress core version, theme, and plugins in use (no single CVE identified for this campaign)
Immediate actions
- Block all known UNC5142 C2 and payload-hosting domains and IPs at DNS/network egress
- Update WordPress core, themes, and plugins on all internet-facing sites immediately
- Deploy file integrity monitoring on WordPress theme/plugin directories and the WordPress database
- Alert on mshta.exe execution and on powershell.exe spawned from mshta.exe with -ep RemoteSigned -w 1 -enc in the command line
- Alert on outbound connections to mediafire.com/file_premium and suspicious GitHub raw-content downloads
Workarounds
- Where immediate patching is not possible, place vulnerable WordPress plugin/theme endpoints behind WAF virtual patching rules
- Disable or remove unused/outdated WordPress plugins and themes that are common compromise vectors
Longer-term hardening
- Implement a Web Application Firewall (WAF) tuned to detect and block malicious JavaScript injection on WordPress
- Restrict PHP execution in wp-content/plugins and wp-content/themes directories
- Deploy WordPress security/hardening plugins (e.g. Wordfence, Sucuri) with active malware scanning
- Monitor for Web3.js library loads (cdn.jsdelivr.net/npm/web3) and eth_call RPC traffic to bsc-dataseed.binance.org as a web-layer detection signal for EtherHiding
- Monitor RTCPeerConnection/STUN usage (stun.l.google.com:19302) on customer-facing web properties as a fingerprinting-evasion indicator
- Monitor and restrict abuse of Cloudflare Pages (*.pages.dev), MediaFire, GitHub, and Backblaze B2 as payload-hosting channels
Timeline of UNC5142 EtherHiding
- Mandiant Threat Defense and Google Threat Intelligence Group begin tracking UNC5142 as a distinct financially motivated cluster.
- Earliest observed CLEARSHORT campaigns use a single smart contract, Base64 encoding, .shop-TLD hosting, and fake Chrome update lures.
- Campaign adds STUN-based IP reconnaissance and fake reCAPTCHA ClickFix lures; hosting expands to Cloudflare *.pages.dev and .icu domains.
- Main three-level smart contract infrastructure deployed on BNB Smart Chain, funded with 0.1 BNB (~$66) from an OKX exchange intermediary wallet.
- Three-contract system refined; landing pages begin using AES-GCM encryption alongside Base64, with Data Privacy agreement and reCAPTCHA lure variants.
- ATOMIC (AMOS) macOS infostealer first observed being distributed via the campaign; spoofed Cloudflare 'Unusual Web Traffic' error lure introduced.
- Secondary smart contract infrastructure deployed, funded with 0.235 BNB (~$152) from the same OKX intermediary wallet that funded the Main infrastructure.
- LUMMAC.V2 (Lumma) and RADTHIEF (Rhadamanthys) infostealers first observed being distributed alongside VIDAR.
- Main and Secondary infrastructures receive coordinated, near-simultaneous payload and lure updates, supporting single-actor attribution.
- Lures refined to an 'Anti-Bot Verification' prompt targeting both Windows and macOS victims.
- Google identifies approximately 14,000 compromised WordPress web pages exhibiting UNC5142/CLEARSHORT injected-JavaScript behavior.
- Last observed UNC5142 campaign activity; GTIG assesses this may reflect an operational pause or tradecraft shift rather than cluster shutdown.
- Google Cloud/Mandiant/GTIG publish 'New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware,' the primary public disclosure of the campaign, including YARA rules and IOCs.
Sources cited for UNC5142 EtherHiding
- New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware
- Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
- UNC5142's "EtherHiding": Threat Actors Weaponize Smart Contracts to Deliver Malware via Hacked WordPress Sites
- UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
- EtherHiding gives cybercriminals access to blockchain networks impervious to takedowns
- UNC5142 Exploits Blockchain to Infect 14,000 WordPress Sites with Malware
- Hackers Leveraging Blockchain: UNC5142's Malware Campaign Targeting WordPress Sites
- New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware (analysis)
- Cybercriminals Weaponize Blockchain Technology to Hide Malware Distribution Networks
Detection coverage for TL-2026-1512
As of 2026-01-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1512 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.