Thousands of web pages misused by hackers to spread malware


  • UNC5142 hacked 14,000+ WordPress sites to distribute malware
  • Malware payloads were sourced from the blockchain, increasing resilience and preventing takedowns
  • ClickFix tricks tricked users into running malicious commands

More than 14,000 WordPress sites were hacked and used as launching pads for the distribution of malware, Google’s Threat Intelligence Group (GTIG) said in a recent report.

Discussing the campaign in depth, GTIG said it is the work of UNC5142, a relatively new threat actor that emerged in late 2023 and ceased operations in late July 2025.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top