Monday, October 20, 2025
67.5 F
New York

Thousands of web pages abused by hackers to spread malware

WordPress logo on mobile
(Image credit: Shutterstock)

  • UNC5142 hacked 14,000+ WordPress sites to distribute malware
  • Malware payloads were fetched from blockchain, boosting resilience and hindering takedowns
  • ClickFix lures tricked users into running malicious commands

More than 14,000 WordPress websites were hacked and used as launchpads for malware distribution, Google’s Threat Intelligence Group (GTIG) said in a recent report.

Discussing the campaign in-depth, GTIG said that it is the work of UNC5142, a relatively new threat actor that emerged in late 2023 and stopped operations in late July 2025.

It is not yet known if the pause is temporary, permanent, or if the group simply pivoted to different techniques. Given their previous success compromising websites and deploying malware, Google believes that the group just improved their obfuscation techniques and still operates in the wild.

Blockchain and ClickFix

In the campaign, UNC5142 would “indiscriminately” target vulnerable WordPress sites – those with flawed plugins, theme files, and in some cases – the WordPress database itself.

These sites would be given a multi-stage JavaScript downloader dubbed CLEARSHOT, that enabled malware distribution. This downloader fetched the stage-two payload from the public blockchain, often using BNB chain.

The use of blockchain is interesting, the researchers found, as it improves resiliency and makes takedowns more difficult:

“The use of blockchain technology for large parts of UNC5142’s infrastructure and operation increases their resiliency in the face of detection and takedown efforts,” the report says.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“Network based protection mechanisms are more difficult to implement for Web3 traffic compared to traditional web traffic given the lack of use of traditional URLs. Seizure and takedown operations are also hindered given the immutability of the blockchain.”

From the public blockchain, the malware would pull a CLEARSHORT landing page from an external server. This landing page would serve the ClickFix social engineering tactic – prompting users to copy and paste a command into the Run program on Windows (or the Terminal app on a Mac) which ultimately downloads the malware.

The landing pages were typically hosted on a Cloudflare .dev page, it was said, and retrieved in an encrypted format.

Via The Hacker News


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Hot this week

Virginia Giuffre thought she might ‘die a sex slave’ at hands of Epstein and his circle, memoir reveals

Noor NanjiCulture reporter and George Wright Getty Images Virginia Giuffre, seen here...

Bangladesh airport inferno estimated to cost $1bn in damages

Osmond ChiaBusiness reporter Watch: Bangladesh's Hazrat Shahjalal International Airport engulfed...

China’s economic growth slows as trade tensions with US flare up

Osmond ChiaBusiness reporter Getty Images The 4.8% growth in the third...

Two dead after Emirates cargo plane skids off Hong Kong runway into sea

Martin YipHong Kong and Stuart Lau Watch: Wreckage of cargo plane...

Reed says ‘job on the line’ over 1.5m housing target as experts warn meeting it unlikely

Justin RowlattBBC Panorama and Anna LamcheBBC News Housing Secretary Steve Reed...

Topics

Virginia Giuffre thought she might ‘die a sex slave’ at hands of Epstein and his circle, memoir reveals

Noor NanjiCulture reporter and George Wright Getty Images Virginia Giuffre, seen here...

Bangladesh airport inferno estimated to cost $1bn in damages

Osmond ChiaBusiness reporter Watch: Bangladesh's Hazrat Shahjalal International Airport engulfed...

China’s economic growth slows as trade tensions with US flare up

Osmond ChiaBusiness reporter Getty Images The 4.8% growth in the third...

Two dead after Emirates cargo plane skids off Hong Kong runway into sea

Martin YipHong Kong and Stuart Lau Watch: Wreckage of cargo plane...

Reed says ‘job on the line’ over 1.5m housing target as experts warn meeting it unlikely

Justin RowlattBBC Panorama and Anna LamcheBBC News Housing Secretary Steve Reed...

Shrapnel hits cars on California highway during Marines celebration

Ana Faguy and Christal HayesLos Angeles California Highway Patrol Officers took photos...

Rachel Reeves blames Brexit deal for long-term damage to economy

Faisal IslamEconomics editor Rachel Reeves chose to stress the long-term...

Indonesia food poisonings and protests test Probowo’s first year in office

Protests and food poisonings test Indonesian president's first year...

Related Articles

Popular Categories