WordPress Sites Hacked: Over 14,000 Compromised to Spread Malware

Spread the love

Key Highlights

  • Threat Actor: A new group called UNC5142 is targeting WordPress sites.
  • Infection Method: They use a multi-stage JavaScript downloader named CLEARSHORT.
  • Innovative Technique: The group employs “EtherHiding” to obscure malicious code on a blockchain.
  • Activity Status: UNC5142 ceased operations in July 2025, but their methods may still pose a risk.

WordPress is one of the most popular content management systems on the Internet. In fact, more than 43 percent of all websites run on WordPress. This makes the latest attack on WordPress sites by a new threat actor all the more concerning.

According to a new report from the Google Threat Intelligence Group (GTIG), a new threat actor codenamed UNC5142 has been successfully hacking into WordPress sites and using a brand new technique to spread malware across the web. UNC5142, according to the report, would find vulnerable WordPress websites often using flawed WordPress themes, plugins, or databases.

SEE ALSO:
Notorious hacker group doxxes ICE and FBI officials in new leak, report says

The targeted WordPress sites would be infected with a CLEARSHORT, multi-stage JavaScript downloader that distributes the malware. The threat group would then deploy a new technique dubbed “EtherHiding,” which is enabled by CLEARSHORT.

Mashable Light Speed

Google describes EtherHiding as “a technique used to obscure malicious code or data by placing it on a public blockchain, such as the BNB Smart Chain.” This use of blockchain to spread malicious code is unique and makes stopping the spread of malware all the more difficult.

See also  Doge Savings May Fall Short of Claims, Report Reveals

The smart contract containing the code on the blockchain would then call up a CLEARSHORT landing page, often hosted on a Cloudflare dev page, that utilizes a ClickFix social engineering tactic. This tactic tricks the website visitor into running malicious commands on their computer via the Windows Run dialog or Mac’s Terminal app.

UNC5142‘s attacks are often financially motivated, according to Google. GTIG says it has been tracking UNC5142 since 2023. However, Google reports that UNC5142 suddenly stopped all activity in July 2025.

This could mean that this new threat actor group, which has been successfully carrying out its malware campaigns, just decided to call it quits. Or it could mean that the threat actor has altered its techniques, successfully obscuring its latest actions, and is still hacking into vulnerable websites today.

best barefoot shoes

Here you can find the original content; the photos and images used in our article also come from this source. We are not their authors; they have been used solely for informational purposes with proper attribution to their original source.

  • David Bridges

    David Bridges

    David Bridges is a media culture writer and social trends observer with over 15 years of experience in analyzing the intersection of entertainment, digital behavior, and public perception. With a background in communication and cultural studies, David blends critical insight with a light, relatable tone that connects with readers interested in celebrities, online narratives, and the ever-evolving world of social media. When he's not tracking internet drama or decoding pop culture signals, David enjoys people-watching in cafés, writing short satire, and pretending to ignore trending hashtags.

    Related Posts

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Money Robot Submitter Review 2026 Money Robot Submitter Review: Powerful Backlink Automation — But Is It Worth…

    Read more

    XPS 13: Dell’s First True Competitor to MacBook Neo

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Dell has introduced the 2026 XPS 13, a compact, lightweight, and nearly portless laptop designed to rival…

    Read more

    You Missed

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    XPS 13: Dell’s First True Competitor to MacBook Neo

    XPS 13: Dell’s First True Competitor to MacBook Neo

    Callum Turner: Navigating Exes and Relationships in Hollywood

    Callum Turner: Navigating Exes and Relationships in Hollywood

    Tesla’s Best Cybertruck Customer: SpaceX’s Surprising Choice

    Tesla’s Best Cybertruck Customer: SpaceX’s Surprising Choice

    Meta Subscriptions Launch Boosts Zuckerberg’s Wealth by $7 Billion

    Meta Subscriptions Launch Boosts Zuckerberg’s Wealth by $7 Billion

    Waka Flocka Expecting His First Child: Exciting Photos Inside

    Waka Flocka Expecting His First Child: Exciting Photos Inside

    Polymarket’s Efforts to Block VPN Access

    Polymarket’s Efforts to Block VPN Access

    Moments From Black Twitter in May That Made Me Laugh

    Moments From Black Twitter in May That Made Me Laugh

    Apple TV and HomePod Mini Launch Expected This Fall

    Apple TV and HomePod Mini Launch Expected This Fall

    AI Subscriptions: Meta Launches New Paid Plans for Facebook and Instagram

    AI Subscriptions: Meta Launches New Paid Plans for Facebook and Instagram