HomeMalware & ThreatsStopAndProtect Exploits Nearly 2,000 Hacked WordPress Sites to Distribute Malware and Steal...

StopAndProtect Exploits Nearly 2,000 Hacked WordPress Sites to Distribute Malware and Steal Data

Published on

spot_img

Rising Cyber Threat: Global Cybercrime Operation Exploits Hacked WordPress Sites for Malware

Recent developments in cybersecurity have brought alarming news to light: a global cybercrime operation is exploiting thousands of compromised WordPress websites as crucial infrastructure for distributing malware, seizing control of infected hosts, and storing stolen documents along with logs meant to track the activities of this malicious endeavor. This revelation comes from researchers at Check Point, who are closely monitoring this sophisticated operation.

At the heart of this operation is a diverse toolkit of criminal software, a tactic that greatly increases its effectiveness. Jaromír Hořejší, a cybersecurity analyst at Check Point Research, emphasized that the operation does not hinge on a single piece of malware. Instead, it utilizes various components that perform different roles, including encrypting files, stealthily pilfering documents, locking screens, and even facilitating real-time communication between the attackers and their unsuspecting victims.

Dubbed StopAndProtect, this extensive campaign has drawn significant attention following the discovery of a corresponding ransomware variant in mid-May 2026. The infection process begins with a ClickFix social engineering attack, triggering a PowerShell command that initiates the downloading of additional .NET tools and load-bearing components. This multi-layer infection chain sets the stage for a complex orchestration of malicious activities.

The campaign is notably systemic, leveraging a network of hacked WordPress sites serving several functions. These compromised sites not only act as hosts for various malware stages but also operate as command-and-control (C2) servers that relay instructions to compromised machines and store crucial logs exfiltrated from victims. Check Point researchers suspect that nearly 2,000 WordPress sites have been infiltrated as part of this overarching operation.

A concerning observation made by the cybersecurity researchers is that many of these compromised websites are running outdated versions of WordPress, exposing them to numerous vulnerabilities. For instance, one compromised site was found to be operating with a 2021 version of WordPress, making it susceptible to approximately 40 known vulnerabilities.

This ongoing campaign employs deceptive tactics to ensnare unsuspecting visitors. Compromised sites are manipulated to present fake ClickFix-style CAPTCHA prompts to users, effectively perpetuating their own infections. The PowerShell command triggered by this ruse evolves into a multi-tiered system designed to facilitate further malicious activities:

  1. Stage 1: A .NET downloader that relays operational statistics to the C2 server and loads subsequent stages.
  2. Stage 2: Another .NET downloader designed to incorporate sandbox checks, alongside extensive logging mechanisms for monitoring.
  3. Stage 3: A more comprehensive phase that comprises six critical components:
    • SilentEncryptor encrypts files on infected computers.
    • NetworkShareScanner spreads malicious code via SMB/USB.
    • VBS Spreader propagates the malware across both hard disks and removable media.
    • LockScreen that locks user input while displaying ransom prompts complete with QR codes for payments.
    • SimpleChatProxy enables real-time interaction between victims and operators.
    • SilentDataCollector captures extensive data from compromised systems and relays it back to the C2 server.

Further complicating matters, recent iterations of the malware have integrated additional functionalities. These include the ability to log keystrokes, exfiltrate information from WhatsApp, and capture screenshots every 30 seconds. This sophisticated evolution indicates a growing trend among cybercriminals to enhance the capability of their tools dramatically.

Further investigation revealed that the threat actors utilize a ZIP archive containing a specific PHP file entitled “uploader-installer.php” intended for the installation of a custom WordPress plugin. This plugin enables anyone with valid credentials to upload arbitrary files—including PHP files—into various directories under the WordPress root. The implications are serious, as this could facilitate remote code execution. Once their objectives are achieved, the plugin strategically deactivates and self-deletes, thereby avoiding detection by security measures.

From mid-May to late July 2026, over 700 archives containing stolen data were identified, including several internal documents and tools. Alarmingly, the operators themselves inadvertently infected their systems with this malware. Among the caught files was a custom automation tool named “fMain.frm,” created specifically to manage compromised WordPress sites more efficiently.

It was discovered that the perpetrators leveraged a malicious “verify” plugin, which overlays original site content with a fake CAPTCHA for visitors who are not using Windows. This plugin springs into action once a file named “activator.php” is uploaded, after which it deletes itself from the site.

Currently, as of July 24, 2026, the StopAndProtect campaign has infiltrated over 6,000 unique IP addresses, with the highest concentrations reported in the U.S., Russia, and India.

Eli Smadja from Check Point summarizes the situation by asserting, “The StopAndProtect campaign underscores how attackers can convert poorly maintained WordPress sites into a distributed network for malware delivery, surveillance, data theft, and ransomware.”

As a precaution, organizations are urged to be vigilant about unexpected CAPTCHA prompts that ask them to execute commands, maintain updated devices and security software, and exit any website requesting unusual actions beyond routine browsing. This growing threat serves as a dire reminder of the importance of proactive cybersecurity measures in an increasingly digital world.

Source link

Latest articles

JFrog Artifactory Vulnerabilities Facilitate Software Supply Chain Attacks

Two Critical Vulnerabilities Identified in JFrog Artifactory: Potential for Supply Chain Compromise Recent investigations have...

A CISO’s Playbook: Understanding Agentic Security in Practice

Autonomous Cybersecurity: Cyberhaven's Revolutionary Approach In the evolving landscape of cybersecurity, Cyberhaven's Office of the...

OpenAI Reduces AI Model Development Pace as Astra Nears Key Cyber Capabilities

OpenAI has recently decided to temporarily slow down the development of its latest cutting-edge...

Kriminal Escapes from Grok, Claude Guardrails Priced at $12.99

Emerging Threat: The Kriminal AI Service Utilizing Grok and Claude for Unregulated Cyber Capabilities In...

More like this

JFrog Artifactory Vulnerabilities Facilitate Software Supply Chain Attacks

Two Critical Vulnerabilities Identified in JFrog Artifactory: Potential for Supply Chain Compromise Recent investigations have...

A CISO’s Playbook: Understanding Agentic Security in Practice

Autonomous Cybersecurity: Cyberhaven's Revolutionary Approach In the evolving landscape of cybersecurity, Cyberhaven's Office of the...

OpenAI Reduces AI Model Development Pace as Astra Nears Key Cyber Capabilities

OpenAI has recently decided to temporarily slow down the development of its latest cutting-edge...