Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

August 26, 2026

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

August 26, 2026

Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown

August 25, 2026
Facebook X (Twitter) Instagram
Wednesday, August 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
News

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Team-CWDBy Team-CWDAugust 26, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.

“The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims,” Check Point Research’s Jaromír Hořejší said.

The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026. The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders.

This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. That said, it’s worth noting that the operation does not always result in ransomware deployment. In most cases, the threat actors have been observed covertly stealing lists of files and then specific files from the systems.

The operation is supported by a cluster of hacked WordPress sites that serve multiple functions –

  • Host malware stages
  • Run as command-and-control (C2) servers to send instructions
  • Store logs exfiltrated from victims

Check Point said it was able to glean more insights into the campaign due to the threat actor’s operational security blunders that exposed detailed infection logs and screenshots from victim machines, as well as the tools used to mass-manage compromised websites. As many as close to 2,000 WordPress sites are estimated to have been hacked as part of the campaign.

Most of the sites have been found to not only run outdated versions of WordPress, but also installed plugins. One of the compromised websites, for instance, runs a WordPress version from 2021, making it susceptible to roughly 40 different vulnerabilities.

These sites are tampered with to serve fake ClickFix-style CAPTCHA prompts to visitors, effectively infecting themselves in the process. The PowerShell command triggered using this method acts as a conduit for a multi-step process –

  • A stage 1 .NET downloader that reports statistics to the C2 server and loads the next stage
  • A stage 2 .NET downloader and loader that incorporates sandbox checks and more logging mechanisms, and launches the main components
  • A stage 3 that includes six components:

    • SilentEncryptor, which encrypts either all currently infected computers or only computers with given host names
    • NetworkShareScanner, which functions like an SMB/USB worm to spread to other devices
    • VBS spreader, which propagates the malware to hard disks and removable media, scans the network, and laterally moves via WMI
    • LockScreen, which blocks user input and displays a ransom message with a payment QR code)
    • SimpleChatProxy, which is a custom chat application for communicating between the victim and operator
    • SilentDataCollector, which generates a list of all drives, encrypts it, and exfiltrates this list to the C2 server. The operator can upload a command file to the server that the stealer reads to harvest specific files.

Newer iterations of the stealer also implement extra features, including a keylogger with valid email address detection, exfiltration from WhatsApp, mapping and unmapping network shares, and capturing screenshots of user activity every 30 seconds.

“An operator may issue a WhatsApp search keyword; both the web and desktop versions are supported,” Check Point said. “The stealer waits until the victim becomes inactive and then uses WhatsApp automation to focus the search box, enter the specified keyword (contact name), open the contact information, and capture a screenshot.”

Further investigation has determined that the threat actors make use of a ZIP archive containing a PHP file (“uploader-installer.php”) to install a custom WordPress plugin, which is used to create a must-use (MU) plugin file that’s responsible for creating a must-use (MU) plugin file in the “wp-content/mu-plugins” directory.

The plugin lets anyone in possession of valid credentials upload arbitrary files, including PHP files, to the WordPress site to almost any path under the WordPress root. The upload of PHP files can pave the way for remote code execution. Once the site has been interfered with, the plugin deactivates itself and self-deletes to sidestep detection.

The uploaded files include stolen data from victim machines, with more than 700 archives identified from mid-May to the end of July 2026. Among those files are internal development files and tools in what appears to be a case of the operator inadvertently infecting themselves. This includes a custom automation utility named “fMain.frm” that’s used to manage compromised WordPress sites.

“This automation tool allows the botnet operator to mass-manage compromised WordPress pages,” Check Point said. “It uses secure upload and delete PHP scripts on compromised websites to upload or delete additional files, activate or deactivate fake-captcha ClickFix, activate or deactivate caching, etc.”

The compromised sites contain a malicious “verify” plugin that overlays the original content with a fake CAPTCHA for Windows visitors. The plugin is activated after the threat actor uploads a file called “activator.php,” after which it deletes itself.

Hořejší told The Hacker News via email that the threat actors make use of custom PHP scripts to manage files uploaded to the WordPress sites. The file management script also serves as a conduit for the installation of the “verify” plugin. The attacks are designed to only target Windows users, and users visiting the sites from Apple macOS or Linux are not affected.

“Based on the file timestamps from one of the compromised websites, we assume that the secure upload script was uploaded first, while the other scripts were likely uploaded as backups,” Hořejší said. “This way, if one or two of them were discovered and deleted, the attackers would still retain access to the compromised websites.”

As of July 24, 2026, the campaign has compromised more than 6,000 unique IP addresses. Most of them are located in the U.S. (1,852), Russia (630), and India (630).

“StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware,” Check Point’s Eli Smadja said. 

“We urge organizations to be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFake Minecraft Clients Deliver WeedHack Malware Despite Takedown
Next Article US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
Team-CWD
  • Website

Related Posts

News

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

August 26, 2026
News

Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown

August 25, 2026
News

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

August 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How it preys on personal data – and how to stay safe

October 23, 2025

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Why that next data breach alert could be a trap

April 18, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.