UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Sites — Threadlinqs Intelligence
As of 2026-01-01, UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Sites is a high-severity malware threat attributed to UNC5142, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-1512 · Severity: HIGH · Status: TRACKING · Category: MALWARE
Attribution: UNC5142 · FINANCIAL
UNC5142, a financially motivated cluster tracked by Mandiant Threat Defense and Google Threat Intelligence Group since late 2023, abused a three-level BNB Smart Chain smart-contract system
UNC5142 compromises WordPress sites running vulnerable core, plugin, or theme versions and injects a multistage JavaScript downloader family tracked as CLEARSHORT into theme files (header.php, footer.php, index.php), plugin directories, or the WordPress database. On page load, CLEARSHORT Stage 1 loads the Web3.js, pako (gzip), and crypto-js libraries and connects to the BNB Smart Chain via the public bsc-dataseed.binance.org RPC node to query a First-Level (router) smart contract, which returns a Base64/gzip-encoded ABI and the address of a Second-Level (logic) smart contract. The Second-Level contract exposes four functions used for victim fingerprinting and reconnaissance -- teaCeremony (dynamic code execution / POST check-ins), shibuyaCrossing (OS/platform identification), asakusaTemple (interaction beaconing), and ginzaLuxury (malicious lure retrieval/decryption) -- and its returned script is directly eval()'d in the victim browser. That script performs WebRTC/STUN-based IP address recovery (querying stun.l.google.com:19302 and POSTing the recovered IP to actor-controlled check-in domains such as saaadnesss[.]shop and lapkimeow[.]icu, later ratatui[.]today) and queries a Third-Level (storage) smart contract that holds an AES-GCM-encrypted CLEARSHORT landing page URL, the AES key, and second-stage payload URLs. The decrypted landing page presents an evolving series of ClickFix-style social-engineering lures -- fake Chrome update prompts, fake reCAPTCHA/Data Privacy dialogs, a spoofed Cloudflare "Unusual Web Traffic" error, and later an "Anti-Bot Verification" prompt for both Windows and macOS -- that trick the victim into executing an attacker-supplied command. This leads to a four-stage delivery chain: an initial dropper (.hta or a .xll file masquerading as an Excel add-in) fetched from Cloudflare Pages (*.pages.dev) or attacker infrastructure; a PowerShell loader (invoked with -ep RemoteSigned -w 1 -enc) that performs AES/TripleDES decryption and defense evasion (including ipconfig /flushdns and Mark-of-the-Web bypasses via xattr -c on macOS or NTFS Zone.Identifier stream removal on Windows); abuse of legitimate services (GitHub, MediaFire, Cloudflare Pages, and in early campaigns Backblaze B2) to host an encrypted payload blob disguised with benign extensions (.mp4, .mp3, .wav, .dat); and finally in-memory, no-disk-write execution of a .NET loader that decrypts and runs the final infostealer payload. UNC5142 operated two parallel smart-contract infrastructures -- a Main system deployed November 24, 2024 and a Secondary system deployed February 18, 2025 -- both funded from the same OKX exchange intermediary wallet and updated in near-lockstep (including a coordinated update on March 3, 2025), which GTIG assesses with high confidence indicates single-actor control. Updates to the on-chain configuration typically cost $0.25-$1.50 in BNB network fees, making the infrastructure extremely cheap to maintain and, because the blockchain component is immutable and publicly distributed, effectively resistant to conventional takedown. GTIG does not attribute the final infostealer payloads to UNC5142 directly and assesses the cluster most likely operates as a stolen-credential/data distribution service selling access to downstream threat actors. No CVE is associated with this campaign; initial access is achieved purely through vulnerable WordPress installations and social engineering rather than a specific software vulnerability. No UNC5142 activity has been observed since July 23, 2025, which GTIG assesses may represent an operational pause or a shift in tradecraft rather than the end of the cluster.
Target sectors: technology, ecommerce, general internet users, cryptocurrency
Target regions: Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.006, T1190, T1554, T1059.001, T1218.005, T1216, T1204.002, T1202, T1140, T1036