A financially motivated hacking group known as UNC5142 is using blockchain smart contracts to distribute information stealing malware across thousands of infected websites. The group has targeted both Windows and macOS users by embedding malicious code inside the BNB Smart Chain, creating one of the most resilient malware delivery systems to date.
According to Google’s Threat Intelligence Group, the attackers compromise vulnerable WordPress sites and hide their payloads within blockchain contracts through a method called EtherHiding. This technique conceals malicious scripts inside public blockchain transactions, making detection and takedown extremely difficult.
Google said it identified about 14,000 web pages linked to the campaign before activity stopped in late July 2025. The pause may indicate an operational change rather than a full shutdown.
The infections use a multi-stage JavaScript downloader named CLEARSHORT, which retrieves malware from the blockchain. The first stage script is injected into WordPress plugins, themes, or even directly into site databases. Once active, it communicates with a malicious smart contract that fetches an encrypted landing page used to trick users into running harmful commands.
These landing pages use ClickFix, a social engineering tactic that prompts victims to execute commands through Windows Run or macOS Terminal. The commands download stealer malware such as Atomic, Lumma, Rhadamanthys, and Vidar, which collect browser data, saved passwords, and cryptocurrency wallet keys.
Researchers believe CLEARSHORT is a variant of ClearFake, a long-running JavaScript malware framework first identified in 2023. The evolution of CLEARSHORT shows growing sophistication, including a three-layer smart contract architecture that allows attackers to change payload URLs or decryption keys without modifying the code on compromised sites.
The group’s latest version uses a Router-Logic-Storage structure that mirrors legitimate software design. Each update costs less than two dollars in blockchain fees, giving the attackers an agile and low-cost way to refresh their operations.
UNC5142 maintains two smart contract infrastructures, one created in late 2024 and another added in early 2025. The dual setup improves resilience and supports quick adjustments during active campaigns.
Google’s analysis suggests the group has achieved consistent success, maintaining steady infection rates for more than a year.
Security analysts warn that the abuse of blockchain for malware delivery marks a new stage in cybercrime. By blending malicious activity with legitimate Web3 traffic, attackers have created a persistent, decentralized threat that is almost impossible to erase.
Read more HERE