StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
ID: e0c9466e-c116-5f86-b92a-3457d90d3a8e
STIX ID: report--e0c9466e-c116-5f86-b92a-3457d90d3a8e
Feed Name: Security Affairs
Check Point Research uncovered the StopAndProtect operation that hijacked nearly 2,000 vulnerable WordPress sites to distribute a multi-component malware toolkit. The campaign uses a fake CAPTCHA (ClickFix) to trick visitors into running a PowerShell one-liner, which chains into .NET downloaders and loaders that can exfiltrate files and screenshots, steal credentials, propagate via SMB/USB, lock screens, and selectively encrypt data; operators also used automated VB6 tools to manage the compromised sites and collected tens of thousands of stolen artifacts between May and July 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
