StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
AI-summarised brief · reviewed before publication
Check Point Research has uncovered a global cybercrime operation dubbed StopAndProtect that hijacks nearly 2,000 WordPress sites to deliver a multi‑component malware toolkit. The campaign begins with a ClickFix‑style social‑engineering prompt that triggers a PowerShell command, launching .NET downloaders and loaders which install ransomware, a SMB/USB worm, lock‑screen modules, a VBS spreader, a chat utility and credential stealers. The actors also exfiltrate files, screenshots and WhatsApp data, using a custom WordPress MU plugin that permits arbitrary file uploads and remote code execution. Researchers observed operational‑security mistakes that exposed infection logs and over 700 data archives, including internal development tools. Most compromised sites run outdated WordPress versions with dozens of known vulnerabilities, facilitating the fake CAPTCHA injection against unsuspecting visitors worldwide.
💡 Why It Matters
- · By turning compromised blogs into a distributed malware delivery network, the attackers bypass traditional defenses and reach victims directly through trusted web traffic, dramatically widening the attack surface.