Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Blockchain-Backed Malware Campaign Hits 14,000+ WordPress Sites

Blockchain-Backed Malware Campaign Hits 14,000+ WordPress Sites

Threat Actor Uses Smart Contracts as Malware Delivery Layer

Kelly Cromley by Kelly Cromley
Oct 19, 2025
in Market News, News
Reading Time: 3 mins read
0
Malware

A large-scale cyber intrusion has been observed in which more than fourteen thousand WordPress websites have been compromised by a financially motivated hacking group labelled UNC5142. According to disclosures from Google’s Threat Intelligence Group, the adversary has been using a tactic researchers describe as EtherHiding, where decentralized blockchain systems are abused to host, conceal, and deliver malicious code in a way that is extremely resistant to disruption.

Investigators reported that UNC5142 targets WordPress installations running outdated or vulnerable plugins and themes. Once access is gained, the attackers embed JavaScript-based droppers inside website code. These droppers are designed to fetch encrypted payloads from smart contracts operating on the BNB Smart Chain. Unlike conventional command-and-control servers that can be dismantled, the decentralized and immutable nature of blockchain infrastructure ensures continued availability of the payloads for as long as the underlying chain remains active.

The loaders deployed through this mechanism execute information-stealing malware such as Atomic, Lumma, and Vidar. These programs are engineered to siphon login credentials, digital wallet keys, browser-stored passwords, and other sensitive personal or financial data. Analysts characterized UNC5142 as a criminally motivated actor that has been active since late 2023, with observable escalation in intensity and geographic reach in recent months. The choice of blockchain not only improves persistence but also hinders attribution efforts, because on-chain transactions typically resolve to anonymous wallet addresses.

Cross-Platform Reach and Technique Diffusion Across Actors

The Google Cloud report noted that the malware delivered through EtherHiding exhibits adaptive properties and is capable of infecting both Windows and macOS devices. Users are generally compromised when they land on tampered pages via deceptive advertisements, redirects, or spoofed update notifications. Similar methodology has been observed among North Korean state-linked clusters, such as UNC5342, indicating that this approach is spreading across distinct threat ecosystems serving both espionage and financial objectives.

Cybersecurity commentators have observed on social media that compromised WordPress sites repeatedly re-infect new visitors because the malicious scripts originate from immutable blockchain contracts rather than from removable servers. Dashboards tracking infections have shown widespread interest and anxiety among security practitioners. Mashable’s reporting underscored the magnitude by reiterating the count of over fourteen thousand breached sites functioning as involuntary malware relays.

Remediation Gaps and Call for Hybrid Defenses

Defensive recommendations circulating among incident responders advise WordPress administrators to immediately modernize plugins, harden authentication, and deploy web application firewalls capable of detecting script-level anomalies. However, experts also stressed that traditional patching does not neutralize malware persistence encoded in smart contracts. Analysts have urged the use of blockchain explorers to identify malicious contracts that may still be distributing payloads to infected clients.

Additional warnings have surfaced around closely related WordPress vulnerabilities such as CVE-2025-3776, which could enable total site compromise when chained with EtherHiding-style scripts. Parallel commentary from industry observers pointed out that blockchain, widely promoted as a secure foundation for finance, now exhibits dual-use characteristics when co-opted by attackers.

Security firms following the case remarked that UNC5142 encrypts payloads with multiple AES layers to obstruct reverse engineering. Reports have linked North Korean clusters refining similar playbooks for direct cryptocurrency theft blended with phishing operations. Analysts argued that the trend highlights an emerging phase in which malicious actors converge web exploitation with on-chain persistence to outpace conventional defense postures.

Strategic Implications

Experts view the campaign as indicative of a broader need for hybrid security architectures combining web-application hardening with blockchain forensics. The diffusion of EtherHiding-style techniques across unrelated threat groups suggests that decentralized infrastructures are becoming a durable part of the cybercrime supply chain. Industry voices cautioned that unless platform providers, blockchain developers, hosting firms, and security vendors coordinate proactive safeguards, decentralized technologies may increasingly serve as durable launchpads for illicit operations.

Previous Post

Datavault AI Moves to Acquire NYIAX in Strategic Web3 Expansion

Next Post

Cardano-Powered Forensic System Goes Live in India

Related Posts

ripple decentralized ledger

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
0

AMINA Bank, a Switzerland-based financial institution regulated by FINMA, has implemented Ripple Payments to improve how transactions flow between blockchain...

chainlink

MapleStory Universe Adopts Chainlink for Cross-Chain Gaming

by Kelly Cromley
Dec 13, 2025
0

MapleStory Universe, a blockchain-based gaming platform that enables players to create and monetize their own interactive experiences, has revealed its...

chainbase

Chainbase and OpenLedger Join Forces to Advance AI-Driven Web3

by Kelly Cromley
Dec 13, 2025
0

Chainbase, widely recognized for its omnichain data ecosystem designed for artificial intelligence, has announced a strategic collaboration with OpenLedger, a...

deepsafe partners with arc

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
0

DeepSafe, a decentralized cryptographic verification layer designed for Web3 and artificial intelligence ecosystems, has announced a formal alignment with ARC...

Italy

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025
0

Italy has taken a decisive step toward modernizing its capital markets with the launch of the country’s first minibond fully...

U.S. Securities and Exchange Commission (SEC)

SEC Approves DTCC Pilot to Tokenize U.S. Securities on Blockchains

by Kelly Cromley
Dec 12, 2025
0

The U.S. Securities and Exchange Commission has authorized a three-year pilot program allowing the clearinghouse responsible for nearly all equity...

Next Post
Cardano

Cardano-Powered Forensic System Goes Live in India

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

ripple decentralized ledger
Market News

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
chainlink
Market News

MapleStory Universe Adopts Chainlink for Cross-Chain Gaming

by Kelly Cromley
Dec 13, 2025
chainbase
Market News

Chainbase and OpenLedger Join Forces to Advance AI-Driven Web3

by Kelly Cromley
Dec 13, 2025
deepsafe partners with arc
Market News

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
Italy
Market News

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.