MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Thousands of web pages abused by hackers to spread malware
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$64,010.00-5.52%
  • ethereumEthereum(ETH)$1,868.64-8.28%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$598.65-4.95%
  • rippleXRP(XRP)$1.32-6.46%
  • usd-coinUSDC(USDC)$1.000.02%
  • solanaSolana(SOL)$78.84-9.70%
  • tronTRON(TRX)$0.281592-1.14%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.053.08%
  • dogecoinDogecoin(DOGE)$0.089916-9.08%
Blockchain Technology

Thousands of web pages abused by hackers to spread malware

Last updated: October 17, 2025 10:00 pm
Published: 4 months ago
Share

ClickFix lures tricked users into running malicious commands

More than 14,000 WordPress websites were hacked and used as launchpads for malware distribution, Google’s Threat Intelligence Group (GTIG) said in a recent report.

Discussing the campaign in-depth, GTIG said that it is the work of UNC5142, a relatively new threat actor that emerged in late 2023 and stopped operations in late July 2025.

It is not yet known if the pause is temporary, permanent, or if the group simply pivoted to different techniques. Given their previous success compromising websites and deploying malware, Google believes that the group just improved their obfuscation techniques and still operates in the wild.

In the campaign, UNC5142 would “indiscriminately” target vulnerable WordPress sites – those with flawed plugins, theme files, and in some cases – the WordPress database itself.

These sites would be given a multi-stage JavaScript downloader dubbed CLEARSHOT, that enabled malware distribution. This downloader fetched the stage-two payload from the public blockchain, often using BNB chain.

The use of blockchain is interesting, the researchers found, as it improves resiliency and makes takedowns more difficult:

“The use of blockchain technology for large parts of UNC5142’s infrastructure and operation increases their resiliency in the face of detection and takedown efforts,” the report says.

“Network based protection mechanisms are more difficult to implement for Web3 traffic compared to traditional web traffic given the lack of use of traditional URLs. Seizure and takedown operations are also hindered given the immutability of the blockchain.”

From the public blockchain, the malware would pull a CLEARSHORT landing page from an external server. This landing page would serve the ClickFix social engineering tactic – prompting users to copy and paste a command into the Run program on Windows (or the Terminal app on a Mac) which ultimately downloads the malware.

The landing pages were typically hosted on a Cloudflare .dev page, it was said, and retrieved in an encrypted format.

Via The Hacker News

Read more on TechRadar

This news is powered by TechRadar TechRadar

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Nasdaq seeks rule change with SEC to trade tokenized stocks
Datavault AI Signs Letter of Intent to Acquire NYIAX, Expanding Patented Information Data Exchange and Commercial Footprint
Why Analysts Favor Ruvi AI (RUVI) Over Shiba Inu (SHIB)? Its Audited Token Is Predicted as The Next Millioniare Maker As 100x Forecast Became Realer Post CMC Listing
ETH Climbs Toward $5,000 While Ozak AI Presale Surges Past $1.8M
SOL slides to $122 while Digitap ($TAP) builds visa-style spending for stablecoins: Best crypto presale

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Security Printing Services Market Size, Segments, Share and Companies (2025-34) – Business Upturn
Next Article Ethereum Price Prediction: ETH Declines After Retesting Daily Resistance at $4,232, But This Cheap Crypto to Buy Could 10x Your Capital – Cryptopolitan
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d