StopAndProtect Leverages Close to 2,000 Compromised WordPress Sites to Distribute Malware and Harvest Data

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Cybersecurity Analysts Uncover Global Malware Operation Leveraging Compromised WordPress Sites

Cybersecurity experts have sounded the alarm regarding a vast international cybercrime scheme that exploits numerous breached WordPress websites as a base for distributing malware.

These infected platforms serve multiple nefarious purposes, including harboring malware, pilfering sensitive documents, and maintaining logs of illicit activities.

According to Jaromír Hořejší of Check Point Research, the scheme does not depend on a singular malware variant; rather, it comprises a comprehensive arsenal of criminal tools that function synergistically.

Some elements are designed to encrypt files, while others stealthily capture documents or seize control of user screens. Additionally, one tool facilitates a real-time conversation between the perpetrators and their targets.

This extensive operation, dubbed StopAndProtect, caught the attention of cybersecurity analysts following the discovery of a ransomware variant bearing the same name in mid-May 2026.

The infection sequence initiates with a sophisticated ClickFix social engineering ploy, culminating in the execution of a PowerShell command that installs further .NET downloaders and loaders.

Subsequently, this series evolves into critical components, which encompass ransomware, an SMB/USB worm, LockScreen, a VBS spoofer, a chat application, and a credential harvesting tool.

Notably, ransomware deployment is not a consistent outcome of this operation; often, the perpetrators are detected covertly siphoning lists and specific files from compromised systems.

The scheme is bolstered by a network of hacked WordPress sites that fulfill various functions:

  • Hosting stages of malware
  • Acting as command-and-control (C2) servers to issue directives
  • Archiving logs obtained from victims

Check Point’s thorough analysis was aided by the operational security mishaps of the attackers, which inadvertently revealed detailed infection logs and screenshots sourced from victimized machines, alongside the mechanisms they utilized for mass-managing compromised websites. Approximately 2,000 WordPress sites are believed to have been infiltrated as part of this scheme.

These afflicted sites primarily operate outdated versions of WordPress and its plugins. For instance, one particular compromised site is running a 2021 iteration of WordPress, rendering it vulnerable to roughly 40 different exploits.

These sites are manipulated to present counterfeit ClickFix-style CAPTCHA prompts to unwitting visitors, effectively initiating their own infection in the process. The PowerShell command enacted through this approach serves as a vehicle for a multi-tiered operation:

  • A stage one .NET downloader that communicates statistics to the C2 server and prepares the subsequent stage.
  • A stage two .NET downloader and loader incorporating sandbox checks and sophisticated logging systems, and which activates the primary components.
  • A stage three featuring six elements:
  • SilentEncryptor, which encrypts all currently infected computers or targets specific host names.
  • NetworkShareScanner, which propagates as an SMB/USB worm to reach additional devices.
  • VBS Spreader, which disseminates malware onto hard drives and removable storage, scans local networks, and navigates laterally via WMI.
  • LockScreen, which obstructs user input while displaying a ransom note complete with a payment QR code.
  • SimpleChatProxy, a custom chat tool facilitating communication between the victim and the operator.
  • SilentDataCollector, which compiles an inventory of all drives, encrypts this data, and exfiltrates it to the C2 server. The operator can upload a command file directing the stealer to target specific files for extraction.

Recent iterations of the data stealer introduce additional capabilities, such as a keylogger with the ability to identify valid email addresses, exfiltrate data from WhatsApp, facilitate network share mapping and unmapping, and capture user activity screenshots at 30-second intervals.

Check Point noted that an operator might issue a search keyword for WhatsApp; both web and desktop variants are accommodated.

The stealer remains inactive until the victim is not engaging and then utilizes WhatsApp automation to search for the designated contact name before capturing a screenshot of the contact information.

Further analysis revealed that the perpetrators utilize a ZIP archive containing a PHP file named “uploader-installer.php” to integrate a custom WordPress plugin.

This plugin is responsible for generating a must-use (MU) plugin file within the “wp-content/mu-plugins” directory.

This plugin, once breached, enables individuals with valid credentials to upload arbitrary files, including PHP scripts, to virtually any path within the WordPress root.

Such file uploads can pave the way for remote code execution. Once the website is compromised, the plugin self-deactivates and deletes itself, thereby evading detection.

Among the uploaded files, analysts discovered stolen data from victim systems, identifying over 700 archives from mid-May through the end of July 2026.

These archives included internal development files and tools, indicating a scenario where the operator inadvertently became infected.

This includes a custom automation tool, “fMain.frm,” employed for managing compromised WordPress sites.

Check Point articulated, This automation tool enables the botnet operator to administer compromised WordPress pages en masse.

It employs secure upload and deletion PHP scripts across affected sites to manage additional file uploads or deletions, activate or deactivate fake CAPTCHA prompts, enable or disable caching, etc.

The compromised sites additionally contain a malicious “verify” plugin that superimposes the original content with a deceptive CAPTCHA for non-Windows users.

This plugin activates upon the threat actor uploading a file entitled “activator.php,” after which it promptly deletes itself.

As of July 24, 2026, the campaign has subdued over 6,000 unique IP addresses, predominantly from the United States (1,852), Russia (630), and India (630).

Close-up of the WordPress app download page on a tablet, showing its logo, rating, and a blue cloud icon.

According to Eli Smadja from Check Point, “The StopAndProtect operation illustrates how assailants can transform innumerable poorly maintained WordPress sites into a decentralized infrastructure for malware dissemination, surveillance, data exfiltration, and ransomware deployment.”

Smadja advises organizations to exercise caution with unexpected CAPTCHA prompts that request users to copy, paste, or execute commands.

Keeping devices and security software up-to-date is critical, along with the immediate departure from any site that solicits atypical interactions outside the browser.

Source link: Thehackernews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading