Connect with us

Security

Exposed: StopAndProtect’s Exploitation of 2,000 Hacked WordPress Sites for Malicious Purposes

Published

on

Global Cybercrime Operation Exploiting Thousands of Hacked WordPress Websites Uncovered

Security experts have identified a widespread cybercrime scheme that leverages a multitude of compromised WordPress sites to facilitate the distribution of malicious software, hijack infected machines, store pilfered documents, screenshots, and activity logs utilized for monitoring the operation’s progress.

“Rather than relying on a single malware strain, this operation employs a comprehensive toolkit of illicit software components that work in tandem – while some elements encrypt files, others surreptitiously extract documents or lock screens, and yet another functions as a live communication channel between the attackers and their targets,” explained Jaromír HoÅ™ejší from Check Point Research.

Referred to as StopAndProtect by the cybersecurity firm following the discovery of a ransomware variant carrying the same name in mid-May 2026, the assault commences with a ClickFix social engineering assault, leading to the execution of a PowerShell command triggering the deployment of additional .NET downloaders and loaders.

This sequence paves the way for the primary components, encompassing ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility, and credential stealer. Notably, the operation doesn’t invariably culminate in ransomware deployment, with the threat actors frequently opting to silently exfiltrate lists of files and specific data from compromised systems.

The operation is propped up by a cluster of compromised WordPress sites performing various roles, including:

  • Hosting malware stages
  • Serving as command-and-control (C2) servers for issuing directives
  • Storing logs extracted from victims

Check Point divulged that the exposure of detailed infection logs, victim machine screenshots, and tools utilized to manage compromised websites due to the threat actor’s operational oversights enabled a deeper understanding of the campaign. Approximately 2,000 WordPress sites are estimated to have fallen victim to this onslaught.

Many of these sites not only operate on outdated WordPress versions but also harbor vulnerable plugins. For instance, one compromised site runs a WordPress version dating back to 2021, rendering it susceptible to around 40 distinct vulnerabilities.

These compromised sites are manipulated to present counterfeit ClickFix-style CAPTCHA prompts to visitors, resulting in self-infection. The PowerShell command activated through this method serves as a conduit for a multi-step process:

  • A stage 1 .NET downloader that communicates statistics to the C2 server and loads the subsequent stage
  • A stage 2 .NET downloader and loader incorporating sandbox checks, enhanced logging mechanisms, and initiation of the primary components
  • A stage 3 housing six components:

    • SilentEncryptor – encrypts all infected computers or specific hosts
    • NetworkShareScanner – acts as an SMB/USB worm for spreading to other devices
    • VBS spreader – propagates malware across hard disks, removable media, scans networks, and laterally moves via WMI
    • LockScreen – immobilizes user input and displays a ransom message with a payment QR code
    • SimpleChatProxy – a custom chat app for communication between victim and operator
    • SilentDataCollector – compiles a list of all drives, encrypts it, and sends it to the C2 server. The operator can upload a command file to the server, which the stealer reads to harvest specific files.

Newer iterations of the data stealer include additional functionalities such as a keylogger with valid email address detection, WhatsApp data exfiltration, network share mapping/unmapping, and capturing user activity screenshots every 30 seconds.

“An operator can prompt a WhatsApp search keyword; support is offered for both web and desktop versions,” noted Check Point. “The stealer waits for the victim’s inactivity, then utilizes WhatsApp automation to search, focus on the keyword (contact name), access contact info, and capture a screenshot.”

Further scrutiny revealed the exploitation of a ZIP archive containing a PHP file (“uploader-installer.php”) to install a custom WordPress plugin, facilitating the creation of a must-use (MU) plugin file in the “wp-content/mu-plugins” directory.

This plugin permits individuals with valid credentials to upload various files, including PHP files, to nearly any path within the WordPress root, potentially leading to remote code execution. Once the site is infiltrated, the plugin deactivates itself and self-removes to evade detection.

Among the uploaded files are pilfered data from victim machines, with over 700 archives identified from mid-May to late July 2026. These files encompass internal development files and tools, indicating a scenario where the operator unwittingly infected themselves. Included is a custom automation tool named “fMain.frm” utilized for managing compromised WordPress sites.

“This automation tool streamlines the botnet operator’s management of compromised WordPress pages, employing secure upload and delete PHP scripts on compromised sites to upload/delete additional files, activate/deactivate fake-captcha ClickFix, enable/disable caching, etc.,” explained Check Point.

The compromised sites house a malevolent “verify” plugin that overlays genuine content with a spurious CAPTCHA for non-Windows visitors. Activation occurs post-upload of a file named “activator.php,” after which the plugin erases itself.

As of July 24, 2026, the operation has impacted over 6,000 distinct IP addresses, with a majority located in the U.S. (1,852), Russia (630), and India (630).

“StopAndProtect exemplifies how threat actors can transform thousands of inadequately maintained WordPress sites into a dispersed criminal network for malware distribution, surveillance, data theft, and ransomware,” highlighted Eli Smadja from Check Point.

“We advise organizations to exercise caution when faced with unexpected CAPTCHA prompts directing them to execute commands, ensure their devices and security software are up to date, and immediately exit websites requesting unusual actions outside the browser.”

See also  Under Attack: Bloody Wolf's Spear-Phishing Campaign Targets Uzbekistan and Russia with NetSupport RAT

Trending