# UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Sites

> UNC5142, a financially motivated cluster tracked by Mandiant Threat Defense and Google Threat Intelligence Group since late 2023, abused a three-level BNB Smart Chain smart-contract system ("EtherHiding") to dynamically store and serve malicious CLEARSHORT JavaScript payload configurations across roughly 14,000 compromised WordPress sites, using evolving social-engineering ClickFix-style lures to deliver VIDAR, LUMMAC.V2 (Lumma), RADTHIEF (Rhadamanthys), and ATOMIC (AMOS) infostealers to Windows and macOS victims. No activity has been observed since July 23, 2025.

- **Published:** 2026-01-01T00:00:00Z
- **Last reviewed:** 2026-01-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1512
- **ID:** TL-2026-1512
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** TRACKING
- **Actor:** UNC5142
- **Detections:** 9 · **IOCs:** 42 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UNC5142 compromises WordPress sites running vulnerable core, plugin, or theme versions and injects a multistage JavaScript downloader family tracked as CLEARSHORT into theme files (header.php, footer.php, index.php), plugin directories, or the WordPress database. On page load, CLEARSHORT Stage 1 loads the Web3.js, pako (gzip), and crypto-js libraries and connects to the BNB Smart Chain via the public bsc-dataseed.binance.org RPC node to query a First-Level (router) smart contract, which returns a Base64/gzip-encoded ABI and the address of a Second-Level (logic) smart contract. The Second-Level contract exposes four functions used for victim fingerprinting and reconnaissance -- teaCeremony (dynamic code execution / POST check-ins), shibuyaCrossing (OS/platform identification), asakusaTemple (interaction beaconing), and ginzaLuxury (malicious lure retrieval/decryption) -- and its returned script is directly eval()'d in the victim browser. That script performs WebRTC/STUN-based IP address recovery (querying stun.l.google.com:19302 and POSTing the recovered IP to actor-controlled check-in domains such as saaadnesss[.]shop and lapkimeow[.]icu, later ratatui[.]today) and queries a Third-Level (storage) smart contract that holds an AES-GCM-encrypted CLEARSHORT landing page URL, the AES key, and second-stage payload URLs. The decrypted landing page presents an evolving series of ClickFix-style social-engineering lures -- fake Chrome update prompts, fake reCAPTCHA/Data Privacy dialogs, a spoofed Cloudflare "Unusual Web Traffic" error, and later an "Anti-Bot Verification" prompt for both Windows and macOS -- that trick the victim into executing an attacker-supplied command. This leads to a four-stage delivery chain: an initial dropper (.hta or a .xll file masquerading as an Excel add-in) fetched from Cloudflare Pages (*.pages.dev) or attacker infrastructure; a PowerShell loader (invoked with -ep RemoteSigned -w 1 -enc) that performs AES/TripleDES decryption and defense evasion (including ipconfig /flushdns and Mark-of-the-Web bypasses via xattr -c on macOS or NTFS Zone.Identifier stream removal on Windows); abuse of legitimate services (GitHub, MediaFire, Cloudflare Pages, and in early campaigns Backblaze B2) to host an encrypted payload blob disguised with benign extensions (.mp4, .mp3, .wav, .dat); and finally in-memory, no-disk-write execution of a .NET loader that decrypts and runs the final infostealer payload. UNC5142 operated two parallel smart-contract infrastructures -- a Main system deployed November 24, 2024 and a Secondary system deployed February 18, 2025 -- both funded from the same OKX exchange intermediary wallet and updated in near-lockstep (including a coordinated update on March 3, 2025), which GTIG assesses with high confidence indicates single-actor control. Updates to the on-chain configuration typically cost $0.25-$1.50 in BNB network fees, making the infrastructure extremely cheap to maintain and, because the blockchain component is immutable and publicly distributed, effectively resistant to conventional takedown. GTIG does not attribute the final infostealer payloads to UNC5142 directly and assesses the cluster most likely operates as a stolen-credential/data distribution service selling access to downstream threat actors. No CVE is associated with this campaign; initial access is achieved purely through vulnerable WordPress installations and social engineering rather than a specific software vulnerability. No UNC5142 activity has been observed since July 23, 2025, which GTIG assesses may represent an operational pause or a shift in tradecraft rather than the end of the cluster.

## MITRE ATT&CK

- T1583.006 Web Services
- T1190 Exploit Public-Facing Application
- T1554 Compromise Host Software Binary
- T1059.001 PowerShell
- T1218.005 Mshta
- T1216 System Script Proxy Execution
- T1204.002 Malicious File
- T1202 Indirect Command Execution
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1580 Cloud Infrastructure Discovery
- T1070 Indicator Removal
- T1553.005 Mark-of-the-Web Bypass
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1614 System Location Discovery
- T1552.001 Credentials In Files
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1219 Remote Access Tools
- T1568 Dynamic Resolution
- T1041 Exfiltration Over C2 Channel

## Sources

- [New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware](https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware/)
- [Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites](https://thehackernews.com/2025/10/hackers-abuse-blockchain-smart.html)
- [UNC5142's "EtherHiding": Threat Actors Weaponize Smart Contracts to Deliver Malware via Hacked WordPress Sites](https://hackersterminal.com/hackers-abuse-blockchain-smart-contracts-to-spread-malware-via-infected-wordpress-sites/)
- [UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts](https://securityonline.info/unc5142-uses-etherhiding-to-deploy-malware-via-bnb-smart-chain-smart-contracts/)
- [EtherHiding gives cybercriminals access to blockchain networks impervious to takedowns](https://blog.barracuda.com/2025/10/31/etherhiding-cybercriminals-blockchain-networks)
- [UNC5142 Exploits Blockchain to Infect 14,000 WordPress Sites with Malware](https://www.webpronews.com/unc5142-exploits-blockchain-to-infect-14000-wordpress-sites-with-malware/)
- [Hackers Leveraging Blockchain: UNC5142's Malware Campaign Targeting WordPress Sites](https://www.businesstechweekly.com/technology-news/hackers-leveraging-blockchain-unc5142s-malware-campaign-targeting-wordpress-sites/)
- [New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware (analysis)](https://gurucul.com/latest-threats/new-group-on-the-block-unc5142-leverages-etherhiding-to-distribute-malware/)
- [Cybercriminals Weaponize Blockchain Technology to Hide Malware Distribution Networks](https://www.siteguarding.com/security-blog/cybercriminals-weaponize-blockchain-technology-to-hide-malware-distribution-networks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1512
