Extensive Cybercrime Operation Utilizes Compromised WordPress Sites
A sweeping cybercrime initiative known as StopAndProtect is exploiting nearly 2,000 infiltrated WordPress websites to disseminate malware, commandeer infected systems, and exfiltrate sensitive information from victims.
In findings published by Check Point Research, it is revealed that StopAndProtect is not reliant on a singular malware variant.
Instead, the perpetrators deploy a multifaceted criminal toolkit, adept at encrypting files, purloining documents and credentials, locking screens, propagating across networks, and even engaging in direct communication with their targets.
The operation commences with a ClickFix social-engineering tactic, designed to deceive users into executing a PowerShell command.
This action activates additional .NET downloaders and loaders, which subsequently install multiple malicious components, including ransomware, credential theft tools, SMB/USB worms, VBS distributors, and screen-locking malware.
Notably, the deployment of ransomware is not invariably the primary aim of these attackers. In numerous documented instances, the criminals have operated covertly, initially compiling inventories of files before proceeding to exfiltrate selected documents, screenshots, and system data.
A salient characteristic of StopAndProtect is its exploitation of compromised WordPress websites. Instead of merely targeting website proprietors, the attackers harness these sites as a distributed network for hosting malware, facilitating command-and-control operations, and archiving stolen data.
Researchers from Check Point have managed to gain unprecedented insight into the workings of this operation, as missteps by the attackers reportedly unveiled infection logs, screenshots from compromised devices, and tools to manage the extensive array of hacked websites.
Many of the affected sites were operating on outdated versions of WordPress and utilized vulnerable plugins.
One notably compromised site was found to be using a WordPress version from 2021, exposing it to approximately 40 known vulnerabilities.
StopAndProtect exemplifies how unpatched online infrastructure can become a force multiplier for cybercriminal activities.
A single vulnerable WordPress website may seem trivial, yet thousands of compromised sites can coalesce to create a formidable malware distribution and command infrastructure.
This campaign underscores the necessity for organizations to adopt a holistic approach to cybersecurity.

Protection efforts cannot solely concentrate on endpoints; instead, websites, plugins, content management systems, and overlooked internet-facing assets must be systematically inventoried, patched, and monitored.
The overarching lesson is clear: today’s vulnerable website may well transform into tomorrow’s platform for cybercriminal endeavors.
Source link: Varindia.com.



