Targeting both Windows and Apple macOS computers, a financially motivated threat actor with the codename UNC5142 has been seen abusing blockchain smart contracts to help spread information thieves like Atomic (AMOS), Lumma, Rhadamanthys (also known as RADTHIEF), and Vidar.
In a research shared with The Hacker News, Google Threat Intelligence Group (GTIG) stated that UNC5142 is distinguished by its usage of hijacked WordPress websites and “EtherHiding,” a technique that obscures dangerous code or data by storing it on a public blockchain, like the BNB Smart Chain.
According to Google, as of June 2025, it has identified over 14,000 web pages with JavaScript injected that had behavior linked to a UNC5142, suggesting that it was indiscriminately targeting WordPress websites that were vulnerable.
The IT company did point out that it hasn’t seen any UNC5142 activity since July 23, 2025, which could indicate a pause or a change in strategy read more about Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
