Criminal Syndicate StopAndProtect Exploits Nearly 2,000 Vulnerable WordPress Blogs for Cryptocurrency Theft
A nefarious group identified by Check Point Research as StopAndProtect has orchestrated a complex operation, leveraging nearly 2,000 inadequately maintained WordPress blogs to disseminate malware that expropriates cryptocurrency wallet seeds, credentials, and files from compromised Windows systems.
The most disconcerting aspect for cryptocurrency holders is the widespread infiltration of reputable sites masquerading as ordinary business blogs.
On August 18, Check Point unveiled these findings, linking a ransomware variant detected in mid-May to a broader scheme encompassing extortion and surveillance.
Unconventional Hosting Tactics
In contrast to contemporary malware campaigns predominantly reliant on commandeered servers, StopAndProtect adopts a distinctive strategy, as articulated by researcher Jaromír Hořejší.
Their ransomware, payloads, command-and-control mechanisms, and repositories for pilfered data are ingeniously housed on WordPress domains that attackers did not need to rent or breach.
This innovative approach is particularly illuminating, Hořejší noted. A single server can host the malicious payload, relay instructions to infiltrated systems, and archive stolen files.
Security Affairs elaborates on this, underscoring the transformation of a compromised site from merely a hacked entity to an operational base for further malicious activities.
The underlying infrastructure is notably neglected, evidenced by Hořejší’s discovery while analyzing the WordPress instance tied to one such domain.
His investigation revealed approximately 40 diverse vulnerabilities within the software dating back to 2021.
Mechanics of a Deceptive CAPTCHA Phishing Scheme
Individuals involved in the cryptocurrency sphere should remain particularly vigilant regarding this emerging threat.
The phishing operation entices Windows users into believing they must complete a CAPTCHA verification to gain access to a website.
However, the CAPTCHA represents a ruse; users attempting to fulfill this requirement will be instructed to input a PowerShell command into their command prompt.
This command initiates the download of .NET payloads, enabling the perpetrator to siphon saved passwords, cryptocurrency wallet seeds, and other sensitive data from the compromised machine.
Moreover, the malware extends its reach by extracting files from shared network directories, external drives, capturing screenshots, and even encrypting the infected computer, subsequently demanding ransom payment.
As reported by Decrypt, users are strongly advised to exercise caution on sites that solicit them to input or paste information, exiting such pages immediately upon such requests.
However, the campaign’s targets extend beyond crypto wallets. Often, the malware is utilized to pilfer files from the victim’s device.
Reports indicate that the malicious actors undertake meticulous scans of the compromised computer, selectively harvesting files deemed most valuable.
Enhanced versions of the malware possess capabilities to log keystrokes, capture screenshots at 30-second intervals, and even commandeer WhatsApp to acquire images from the victim’s contact list.
Unintentional Revelations from the Attackers’ Own Servers
Crucial insights into the StopAndProtect operation emerged inadvertently from the criminals’ own inadequate security protocols, leaving directories and log files accessible on the web.
Check Point theorizes that an adversary’s device may have been compromised, leading to the unintentional upload of sensitive files to their server.
Among the uncovered data, Hořejší located the source code for an automation tool employed by the criminals to manage the compromised websites.
This tool, crafted in legacy Visual Basic 6, affords the criminals the ability to remotely activate the CAPTCHA phishing interface, redirect unwitting visitors, and update malware on the infiltrated domains.

Text files accompanying the tool contain a compendium of nearly 2,000 domains that have been utilized as phishing platforms.
The log files also enhanced the researcher’s understanding of the attack’s magnitude. As of July 24, the campaign had compromised over 6,000 unique IP addresses, including 1,852 located in the United States, along with 630 each from Russia and India.
Between mid-May and late July, researchers unearthed more than 700 archives of pilfered files. Notably, one of the unsecured directories housed in excess of 20,000 screenshots documenting the screens of victimized computers.
Source link: Cryptopolitan.com.


