Extensive Cybercrime Network Exploits Outdated WordPress Sites
- Investigators unveil a sprawling cybercrime nexus operating from compromised computers and obsolete WordPress domains.
- The “StopAndProtect” inquiry highlights the pivotal role of the WordPress content management system, whose core and plugins were systematically exploited.
- A staggering 2,000 WordPress sites fell victim to this malevolent network.
Check Point Research has recently exposed a global cybercrime syndicate, which thrived through an extensive web of WordPress websites.
The “StopAndProtect” investigation uncovered a network consisting of 5,000 compromised machines across various countries, coupled with 2,000 infected WordPress domains.
Currently, WordPress dominates the content management system landscape, powering approximately 43% of all websites globally, making it the most endorsed platform.
Its versatility caters to a wide array of online presences, from single-page portfolios and simple blogs to extensive news portals and e-commerce platforms.
The research team identified critical lapses that betrayed the crime ring’s operations. These blunders included internal documentation like screenshots, logs of affected users, and references to commandeered domains.
While these revelations may provide some reassurance, the findings raise substantial concerns about the security integrity of WordPress sites.
Mechanisms Behind StopAndProtect’s Operations
WordPress has historically attracted cybercriminals seeking a relatively unguarded terrain to deploy malware and establish botnets.
Despite this notoriety, the platform’s free and open-source nature, combined with simple installation processes and robust plugin ecosystems, facilitates widespread adoption.
Initially referred to as a ransomware variant discovered earlier in 2026, Check Point Research decided to expand the “StopAndProtect” nomenclature to encompass the broader operations of the network, as its activities exceeded mere ransomware distribution.
Eli Smadja from Check Point Research articulated the situation: “The StopAndProtect case exemplifies how malicious actors can transform thousands of inadequately maintained WordPress sites into a distributed criminal infrastructure designed for malware dissemination, surveillance, data exfiltration, and ransomware attacks.”
The Vulnerability of WordPress Domains
With a significant number of WordPress installations affected by the cybercrime ring, alongside the platform’s preeminence in the CMS sphere, it is imperative to question: is WordPress still a secure option for users?
Our investigative findings advocate that organizations remain vigilant regarding unforeseen CAPTCHA prompts that prompt unusual actions, and ensure their devices and security software are consistently updated.
It is equally crucial to cease engagement with any website demanding uncharacteristic procedures outside the browser, Smadja further advised.
A considerable number of small enterprises depend on WordPress not only for public-facing digital portfolios but for various internal functionalities as well.
The StopAndProtect investigation revealed one particular site operating an obsolete version of WordPress, which was riddled with approximately 40 vulnerabilities.

To mitigate risks associated with using WordPress, the most expedient remedy is to confirm that all websites are updated to the latest version, along with ensuring plugins are functioning correctly and are thoroughly updated.
Establishing a regular update protocol for WordPress can substantially diminish the likelihood of hijacking incidents. Such a strategy should be complemented by utilizing a web hosting service that actively monitors for irregularities and suspicious activities.
Source link: Techradar.com.


