logo

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

ID: e0c9466e-c116-5f86-b92a-3457d90d3a8e

STIX ID: report--e0c9466e-c116-5f86-b92a-3457d90d3a8e

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Pierluigi Paganini

...
...

Check Point Research uncovered the StopAndProtect operation that hijacked nearly 2,000 vulnerable WordPress sites to distribute a multi-component malware toolkit. The campaign uses a fake CAPTCHA (ClickFix) to trick visitors into running a PowerShell one-liner, which chains into .NET downloaders and loaders that can exfiltrate files and screenshots, steal credentials, propagate via SMB/USB, lock screens, and selectively encrypt data; operators also used automated VB6 tools to manage the compromised sites and collected tens of thousands of stolen artifacts between May and July 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.