• UNC5142 hacked 14,000+ WordPress sites to distribute malware
  • Malware payloads were fetched from blockchain, boosting resilience and hindering takedowns
  • ClickFix lures tricked users into running malicious commands

More than 14,000 WordPress websites were hacked and used as launchpads for malware distribution, Google’s Threat Intelligence Group (GTIG) said in a recent report.

Discussing the campaign in-depth, GTIG said that it is the work of UNC5142, a relatively new threat actor that emerged in late 2023 and stopped operations in late July 2025.



Source link