Server Mistake Exposes StopAndProtect’s Hacked WordPress Network
ID: 6028ae7a-7230-5686-aa93-6a2376597045
STIX ID: report--6028ae7a-7230-5686-aa93-6a2376597045
Feed Name: HackRead
Check Point Research uncovered "StopAndProtect", a criminal operation that used nearly 2,000 hacked WordPress sites to show fake CAPTCHAs that tricked visitors into running PowerShell; multi-stage PowerShell and .NET loaders installed components for credential theft, screenshots, keystroke logging, SMB/USB/Network spreading and occasional ransomware. A misconfigured site exposed operational files and logs — roughly 31,000 screenshots, 700+ archives of stolen data and logs with >6,000 unique IPs — revealing operator source code, lists of compromised domains and the mu-plugins backdoor (wp-sec.php); recommended mitigations include updating WordPress/plugins, inspecting mu-plugins for unauthorized files, reviewing server logs and never executing PowerShell commands from CAPTCHA pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
