All threat actors

UNC5142

Alert me

A financially motivated cluster active since late 2023 that compromises WordPress sites and uses blockchain-based EtherHiding infrastructure to distribute information stealers. Its CLEARFAKE and CLEARSHORT campaigns frequently use fake browser updates or ClickFix-style social engineering.

Create a free account to see the reports

Sign in or create a free account to see every report that names UNC5142.

Create free account