Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Blockchain-Backed Malware Campaign Hits 14,000+ WordPress Sites

Blockchain-Backed Malware Campaign Hits 14,000+ WordPress Sites

Threat Actor Uses Smart Contracts as Malware Delivery Layer

Kelly Cromley by Kelly Cromley
Oct 19, 2025
in Market News, News
Reading Time: 3 mins read
0
Malware

A large-scale cyber intrusion has been observed in which more than fourteen thousand WordPress websites have been compromised by a financially motivated hacking group labelled UNC5142. According to disclosures from Google’s Threat Intelligence Group, the adversary has been using a tactic researchers describe as EtherHiding, where decentralized blockchain systems are abused to host, conceal, and deliver malicious code in a way that is extremely resistant to disruption.

Investigators reported that UNC5142 targets WordPress installations running outdated or vulnerable plugins and themes. Once access is gained, the attackers embed JavaScript-based droppers inside website code. These droppers are designed to fetch encrypted payloads from smart contracts operating on the BNB Smart Chain. Unlike conventional command-and-control servers that can be dismantled, the decentralized and immutable nature of blockchain infrastructure ensures continued availability of the payloads for as long as the underlying chain remains active.

The loaders deployed through this mechanism execute information-stealing malware such as Atomic, Lumma, and Vidar. These programs are engineered to siphon login credentials, digital wallet keys, browser-stored passwords, and other sensitive personal or financial data. Analysts characterized UNC5142 as a criminally motivated actor that has been active since late 2023, with observable escalation in intensity and geographic reach in recent months. The choice of blockchain not only improves persistence but also hinders attribution efforts, because on-chain transactions typically resolve to anonymous wallet addresses.

Cross-Platform Reach and Technique Diffusion Across Actors

The Google Cloud report noted that the malware delivered through EtherHiding exhibits adaptive properties and is capable of infecting both Windows and macOS devices. Users are generally compromised when they land on tampered pages via deceptive advertisements, redirects, or spoofed update notifications. Similar methodology has been observed among North Korean state-linked clusters, such as UNC5342, indicating that this approach is spreading across distinct threat ecosystems serving both espionage and financial objectives.

Cybersecurity commentators have observed on social media that compromised WordPress sites repeatedly re-infect new visitors because the malicious scripts originate from immutable blockchain contracts rather than from removable servers. Dashboards tracking infections have shown widespread interest and anxiety among security practitioners. Mashable’s reporting underscored the magnitude by reiterating the count of over fourteen thousand breached sites functioning as involuntary malware relays.

Remediation Gaps and Call for Hybrid Defenses

Defensive recommendations circulating among incident responders advise WordPress administrators to immediately modernize plugins, harden authentication, and deploy web application firewalls capable of detecting script-level anomalies. However, experts also stressed that traditional patching does not neutralize malware persistence encoded in smart contracts. Analysts have urged the use of blockchain explorers to identify malicious contracts that may still be distributing payloads to infected clients.

Additional warnings have surfaced around closely related WordPress vulnerabilities such as CVE-2025-3776, which could enable total site compromise when chained with EtherHiding-style scripts. Parallel commentary from industry observers pointed out that blockchain, widely promoted as a secure foundation for finance, now exhibits dual-use characteristics when co-opted by attackers.

Security firms following the case remarked that UNC5142 encrypts payloads with multiple AES layers to obstruct reverse engineering. Reports have linked North Korean clusters refining similar playbooks for direct cryptocurrency theft blended with phishing operations. Analysts argued that the trend highlights an emerging phase in which malicious actors converge web exploitation with on-chain persistence to outpace conventional defense postures.

Strategic Implications

Experts view the campaign as indicative of a broader need for hybrid security architectures combining web-application hardening with blockchain forensics. The diffusion of EtherHiding-style techniques across unrelated threat groups suggests that decentralized infrastructures are becoming a durable part of the cybercrime supply chain. Industry voices cautioned that unless platform providers, blockchain developers, hosting firms, and security vendors coordinate proactive safeguards, decentralized technologies may increasingly serve as durable launchpads for illicit operations.

Previous Post

Datavault AI Moves to Acquire NYIAX in Strategic Web3 Expansion

Next Post

Cardano-Powered Forensic System Goes Live in India

Related Posts

India

ICAI and CAG Push for Blockchain-Enabled Autonomous Audits

by Kelly Cromley
Dec 7, 2025
0

The Institute of Chartered Accountants of India (ICAI) and the Office of the Comptroller and Auditor General (CAG) are jointly...

gafin partners with tauntai

GaFin and tauntAI Join Forces to Advance AI-Powered Web3 Gaming

by Kelly Cromley
Dec 7, 2025
0

GaFin, a well-known Web3 GameFi platform, has announced a collaboration with tauntAI, a rising SocialFi ecosystem built on Web3 frameworks....

21dao partners with tilted

21 DAO and Tilted Partner to Build AI-Powered Web3 Ecosystem

by Kelly Cromley
Dec 7, 2025
0

21 DAO, the decentralized organization behind the task-driven economy platform TasKVerse, has announced a new partnership with Tilted, an AI-powered...

kingdomstarter partners with helios

KingdomStarter and Helios Forge Alliance to Advance Blockchain Innovation

by Kelly Cromley
Dec 7, 2025
0

The blockchain sector is witnessing increasing collaboration as platforms seek to overcome fragmentation and improve accessibility. KingdomStarter, a prominent multi-chain...

miro partners with aether network

MIRO–Aether Alliance Targets Faster, Smarter Web3 Payments

by Kelly Cromley
Dec 6, 2025
0

A new strategic collaboration has been announced between Bitcoin-based payment platform MIRO and Aether Network, a modular blockchain project focused...

KRW1

KRW1 Stablecoin Expands to Polygon, Boosting Real-Time Web3 Payments

by Kelly Cromley
Dec 6, 2025
0

South Korean digital asset custodian BDACS has moved its KRW-backed stablecoin, KRW1, into full deployment on the Polygon blockchain, concluding...

Next Post
Cardano

Cardano-Powered Forensic System Goes Live in India

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

India
Market News

ICAI and CAG Push for Blockchain-Enabled Autonomous Audits

by Kelly Cromley
Dec 7, 2025
gafin partners with tauntai
Market News

GaFin and tauntAI Join Forces to Advance AI-Powered Web3 Gaming

by Kelly Cromley
Dec 7, 2025
21dao partners with tilted
Market News

21 DAO and Tilted Partner to Build AI-Powered Web3 Ecosystem

by Kelly Cromley
Dec 7, 2025
kingdomstarter partners with helios
Market News

KingdomStarter and Helios Forge Alliance to Advance Blockchain Innovation

by Kelly Cromley
Dec 7, 2025
miro partners with aether network
Bitcoin News

MIRO–Aether Alliance Targets Faster, Smarter Web3 Payments

by Kelly Cromley
Dec 6, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.