2,000 Compromised WordPress Websites Turn into Hazards for Cryptocurrency Users

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Criminal Syndicate StopAndProtect Exploits Nearly 2,000 Vulnerable WordPress Blogs for Cryptocurrency Theft

A nefarious group identified by Check Point Research as StopAndProtect has orchestrated a complex operation, leveraging nearly 2,000 inadequately maintained WordPress blogs to disseminate malware that expropriates cryptocurrency wallet seeds, credentials, and files from compromised Windows systems.

The most disconcerting aspect for cryptocurrency holders is the widespread infiltration of reputable sites masquerading as ordinary business blogs.

On August 18, Check Point unveiled these findings, linking a ransomware variant detected in mid-May to a broader scheme encompassing extortion and surveillance.

Unconventional Hosting Tactics

In contrast to contemporary malware campaigns predominantly reliant on commandeered servers, StopAndProtect adopts a distinctive strategy, as articulated by researcher Jaromír Hořejší.

Their ransomware, payloads, command-and-control mechanisms, and repositories for pilfered data are ingeniously housed on WordPress domains that attackers did not need to rent or breach.

This innovative approach is particularly illuminating, Hořejší noted. A single server can host the malicious payload, relay instructions to infiltrated systems, and archive stolen files.

Security Affairs elaborates on this, underscoring the transformation of a compromised site from merely a hacked entity to an operational base for further malicious activities.

The underlying infrastructure is notably neglected, evidenced by Hořejší’s discovery while analyzing the WordPress instance tied to one such domain.

His investigation revealed approximately 40 diverse vulnerabilities within the software dating back to 2021.

Mechanics of a Deceptive CAPTCHA Phishing Scheme

Individuals involved in the cryptocurrency sphere should remain particularly vigilant regarding this emerging threat.

The phishing operation entices Windows users into believing they must complete a CAPTCHA verification to gain access to a website.

However, the CAPTCHA represents a ruse; users attempting to fulfill this requirement will be instructed to input a PowerShell command into their command prompt.

This command initiates the download of .NET payloads, enabling the perpetrator to siphon saved passwords, cryptocurrency wallet seeds, and other sensitive data from the compromised machine.

Moreover, the malware extends its reach by extracting files from shared network directories, external drives, capturing screenshots, and even encrypting the infected computer, subsequently demanding ransom payment.

As reported by Decrypt, users are strongly advised to exercise caution on sites that solicit them to input or paste information, exiting such pages immediately upon such requests.

However, the campaign’s targets extend beyond crypto wallets. Often, the malware is utilized to pilfer files from the victim’s device.

Reports indicate that the malicious actors undertake meticulous scans of the compromised computer, selectively harvesting files deemed most valuable.

Enhanced versions of the malware possess capabilities to log keystrokes, capture screenshots at 30-second intervals, and even commandeer WhatsApp to acquire images from the victim’s contact list.

Unintentional Revelations from the Attackers’ Own Servers

Crucial insights into the StopAndProtect operation emerged inadvertently from the criminals’ own inadequate security protocols, leaving directories and log files accessible on the web.

Check Point theorizes that an adversary’s device may have been compromised, leading to the unintentional upload of sensitive files to their server.

Among the uncovered data, Hořejší located the source code for an automation tool employed by the criminals to manage the compromised websites.

This tool, crafted in legacy Visual Basic 6, affords the criminals the ability to remotely activate the CAPTCHA phishing interface, redirect unwitting visitors, and update malware on the infiltrated domains.

cybersecurity-data-safety-firewall-malware-ransomware-hacking

Text files accompanying the tool contain a compendium of nearly 2,000 domains that have been utilized as phishing platforms.

The log files also enhanced the researcher’s understanding of the attack’s magnitude. As of July 24, the campaign had compromised over 6,000 unique IP addresses, including 1,852 located in the United States, along with 630 each from Russia and India.

Between mid-May and late July, researchers unearthed more than 700 archives of pilfered files. Notably, one of the unsecured directories housed in excess of 20,000 screenshots documenting the screens of victimized computers.

Source link: Cryptopolitan.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading