Ad Code

Ticker

6/recent/ticker-posts

Sponsored by.

Chatbot AI, Voice AI and Employee AI. IndustryStandard.com - Become your own Boss!

Yehey.com - StopAndProtect Malware Hijacks 2,000 WordPress Sites: How to Stay Safe

Image courtesy by QUE.com

A Massive Cybercrime Operation Exploiting WordPress Infrastructure

Cybersecurity researchers have uncovered a sprawling global cybercrime operation known as StopAndProtect that has compromised nearly 2,000 WordPress websites, transforming them into a distributed malware delivery and data theft network. Discovered by Check Point Research in mid-May 2026, the campaign represents a disturbing evolution in how threat actors weaponize poorly maintained websites to serve as command-and-control infrastructure, malware hosts, and data exfiltration repositories.

What makes StopAndProtect particularly alarming is its multi-layered toolkit. Rather than relying on a single strain of malware, the operation deploys an entire ecosystem of criminal software working in concert — components that encrypt files, silently steal documents, lock screens, and even establish live chat channels between attackers and their victims.

How the Infection Chain Works

The StopAndProtect campaign begins with a ClickFix social engineering attack, a technique that tricks users into executing malicious PowerShell commands by presenting fake CAPTCHA verification prompts. Once initiated, the infection follows a sophisticated three-stage process:

  • Stage 1: A .NET downloader reports statistics to the command-and-control server and loads the next stage of the payload
  • Stage 2: A second .NET downloader and loader incorporates sandbox detection checks and additional logging mechanisms before launching the main components
  • Stage 3: Six distinct malicious components are deployed simultaneously, each serving a specific criminal function

The Six Components of the StopAndProtect Toolkit

Once fully deployed, the StopAndProtect operation unleashes six powerful modules on infected systems:

  • SilentEncryptor — Encrypts files on all infected computers or targets specific host names, functioning as the ransomware component
  • NetworkShareScanner — Operates as an SMB and USB worm, spreading laterally to other devices on the network
  • VBS Spreader — Propagates malware to hard disks and removable media, scans the network, and moves laterally via WMI
  • LockScreen — Blocks all user input and displays a ransom message complete with a payment QR code
  • SimpleChatProxy — A custom chat application enabling direct communication between the victim and the attacker
  • SilentDataCollector — Generates encrypted lists of all drives, exfiltrates them to the C2 server, and allows operators to harvest specific files on demand

WordPress Sites as Criminal Infrastructure

The operation's reliance on hacked WordPress sites is perhaps its most innovative and concerning aspect. These compromised websites serve three critical functions for the attackers: hosting malware stages, acting as command-and-control servers to issue instructions, and storing logs exfiltrated from victim machines. The threat actors install a custom WordPress plugin via a PHP uploader file, which creates a must-use plugin in the wp-content/mu-plugins directory.

This malicious plugin allows anyone with valid credentials to upload arbitrary files, including PHP files, to nearly any path under the WordPress root directory — effectively enabling remote code execution. Once installed, the plugin deactivates itself and self-deletes to avoid detection.

Most of the compromised sites were running severely outdated WordPress versions and plugins. One identified site was running a WordPress version from 2021, leaving it vulnerable to approximately 40 known vulnerabilities. This highlights a persistent problem in the web security ecosystem: website administrators who fail to maintain current software versions create fertile ground for large-scale exploitation.

Advanced Surveillance and Data Theft Capabilities

Newer iterations of the StopAndProtect stealer have introduced increasingly invasive surveillance features. The malware now includes a keylogger with valid email address detection, the ability to exfiltrate data from WhatsApp, network share mapping capabilities, and automated screenshot capture every 30 seconds.

Perhaps most concerning is the WhatsApp automation feature. Operators can issue a search keyword, and the stealer will wait until the victim becomes inactive, then use WhatsApp automation to focus the search box, enter the specified contact name, open the contact information, and capture a screenshot — all without the victim's knowledge.

The Scale of the Campaign

As of July 24, 2026, the StopAndProtect campaign had compromised more than 6,000 unique IP addresses across the globe. The majority of victims were located in the United States (1,852), followed by Russia (630) and India (630). Check Point researchers identified over 700 stolen data archives uploaded to compromised WordPress sites between mid-May and the end of July 2026.

In a remarkable turn of events, the threat actors' own operational security failures exposed detailed infection logs, screenshots from victim machines, and the tools used to mass-manage the compromised websites. Among the leaked files were internal development tools, including a custom automation utility that allows the operator to mass-manage hacked WordPress pages, toggle fake CAPTCHA prompts, and control caching behavior across the entire network of compromised sites.

Protecting Your Organization and Website

The StopAndProtect campaign underscores several critical security lessons for both website owners and individual users:

For WordPress Site Administrators

  • Keep WordPress core and plugins updated — The majority of compromised sites were running software versions years out of date
  • Monitor for unauthorized plugins — Regularly scan the mu-plugins directory for unfamiliar files
  • Implement web application firewalls — WAFs can detect and block malicious upload attempts
  • Use strong authentication — Enable two-factor authentication and use application passwords for API access
  • Audit file permissions — Ensure PHP files cannot be written to arbitrary paths

For Individual Users and Organizations

  • Be wary of fake CAPTCHA prompts — The ClickFix technique is the primary entry point for this campaign
  • Never execute PowerShell commands from untrusted sources or verification prompts
  • Deploy endpoint detection and response solutions — Modern EDR tools can identify the multi-stage loading behavior
  • Maintain offline backups — The ransomware component can encrypt files across entire networks
  • Monitor network traffic — Watch for unusual outbound connections to unfamiliar WordPress domains

What This Means for the Threat Landscape

The StopAndProtect operation demonstrates how attackers can repurpose thousands of poorly maintained websites into a powerful distributed criminal infrastructure. By combining social engineering, multi-stage malware deployment, and legitimate web platforms as command-and-control channels, the campaign blurs the line between traditional cybercrime and sophisticated nation-state level operations.

As Check Point's Eli Smadja noted, this campaign shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware. The lesson is clear: website maintenance is no longer just a best practice — it is a critical component of the global cybersecurity ecosystem.

Organizations and individuals alike must remain vigilant, keep their systems updated, and invest in layered security defenses that can detect and respond to multi-stage attack campaigns before they cause irreparable damage.




Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous

Articles published by QUE.COM Intelligence via Yehey.com website.

Post a Comment

0 Comments

Comments

Ad Code