logo

Server Mistake Exposes StopAndProtect’s Hacked WordPress Network

ID: 6028ae7a-7230-5686-aa93-6a2376597045

STIX ID: report--6028ae7a-7230-5686-aa93-6a2376597045

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Waqas

...
...

Check Point Research uncovered "StopAndProtect", a criminal operation that used nearly 2,000 hacked WordPress sites to show fake CAPTCHAs that tricked visitors into running PowerShell; multi-stage PowerShell and .NET loaders installed components for credential theft, screenshots, keystroke logging, SMB/USB/Network spreading and occasional ransomware. A misconfigured site exposed operational files and logs — roughly 31,000 screenshots, 700+ archives of stolen data and logs with >6,000 unique IPs — revealing operator source code, lists of compromised domains and the mu-plugins backdoor (wp-sec.php); recommended mitigations include updating WordPress/plugins, inspecting mu-plugins for unauthorized files, reviewing server logs and never executing PowerShell commands from CAPTCHA pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.