StopAndProtect Leverages Nearly 2000 WordPress Sites for Attacks – Veri Sızıntısı

StopAndProtect Uses Nearly 2000 Hacked WordPress Sites

Cybersecurity researchers have uncovered a global cybercrime operation dubbed StopAndProtect. Attackers are using a network of nearly 2,000 hacked WordPress sites to conduct a multi-stage attack involving ransomware and data theft.

A cybersecurity concept image showing broken chain links with the WordPress logo in the background.

What Happened

The cybersecurity firm Check Point has uncovered a global cybercrime operation, which it has named "StopAndProtect." Researchers found that the attackers are using a complex infrastructure of nearly 2,000 hacked WordPress-based websites. This massive network is utilized to disseminate malware, remotely command infected systems, and store data stolen from victims. At the core of the attack is the "StopAndProtect" ransomware family, discovered in mid-May 2026, which gives the operation its name.

However, the operation is not limited to a single piece of malware. As stated by Jaromír Hořejší of Check Point Research, this attack relies on a whole toolkit of criminal software working together. This toolkit includes components that encrypt files, modules that silently steal documents, tools that lock the victim's screen, and even a custom chat utility that allows live communication between attackers and their victims. This versatile structure enables attackers to pursue flexible strategies based on their targets. While ransomware is deployed in some cases, in many instances, the attackers' main objective was observed to be exfiltrating lists of files from systems and then covertly stealing specific documents. This indicates that the operation is not solely focused on financial gain but also has data espionage objectives.

Data Exfiltrated

Data theft is one of the primary goals of the StopAndProtect operation. The data stolen by the attackers from victim systems is quite diverse. It includes sensitive documents, screenshots taken to monitor the victim's activities, and activity logs created to track the status of the operation. A component of the attack, named "SilentDataCollector," first generates a list of all drives on the victim's system, encrypts this list, and sends it to the command-and-control server. The attacker can then upload a command file to the server specifying which files to steal, enabling targeted data theft.

The data collection capabilities do not end there. Newer versions of the malware include a keylogger feature that records keystrokes. This keylogger is particularly adept at detecting valid email addresses, providing valuable information for phishing attacks or identity theft. Additionally, the software has advanced espionage features, such as exfiltrating data from the WhatsApp desktop application, mapping network shares, and unmapping them. This variety reveals that the attackers can gather in-depth information about the victim and can use the stolen data for various malicious purposes.

How The Attack Happened

The attack chain begins with a "ClickFix" social engineering tactic designed to deceive users. Victims are typically tricked by a fake CAPTCHA verification or a similar lure into unknowingly executing a malicious PowerShell command. This initial step triggers a multi-stage infection process.

Compromised WordPress Infrastructure

The operation's infrastructure is built upon nearly 2,000 WordPress sites compromised by the attackers. These sites are used for three main purposes: hosting malware stages, acting as command-and-control (C2) servers to send instructions to infected systems, and storing data exfiltrated from victims. Check Point noted that they were able to gain significant insights into the infrastructure and operational details due to the attackers' operational security blunders. Most of the compromised sites were found to be running outdated versions of WordPress and its plugins. For example, one of the analyzed sites was running a 2021 version of WordPress, making it vulnerable to approximately 40 different security flaws.

Multi-Stage Infection Process

After the PowerShell command is executed, the infection process proceeds in the following steps:

  • Stage 1: A .NET downloader is activated. This component's task is to report infection statistics to the C2 server and download the next-stage loader onto the system.
  • Stage 2: A more advanced .NET downloader and loader is executed. This stage includes "sandbox" checks to determine if it is in a virtual or analysis environment, along with more detailed logging mechanisms. If successful, it launches the main malware components.
  • Stage 3: This stage comprises the six core components of the operation:
    • SilentEncryptor: The ransomware module that, on command, encrypts files on all currently infected computers or targets only those with specific host names.
    • NetworkShareScanner: Acts like an SMB/USB worm. It aims to spread to other devices by propagating through network shares and removable USB drives.
    • VBS Spreader: Propagates the malware by copying it to hard disks and removable media. It also scans the network and performs lateral movement via Windows Management Instrumentation (WMI).
    • LockScreen: Prevents the victim from using their computer, locks the screen, and displays a ransom note that includes a QR code for payment.
    • SimpleChatProxy: A custom-built chat application designed for communication between the victim and the attacker, used for processes like ransom negotiation.
    • SilentDataCollector: Creates a list of all drives, encrypts this list, and exfiltrates it to the C2 server. The operator can then choose specific files from this list to be stolen.

Who Is Affected

The source article does not provide specific details about the companies, sectors, or geographic regions affected by the attack. However, given that the operation is global and the diversity of the compromised WordPress sites, it is understood that the victims could be any internet users visiting these sites. The attack appears to be opportunistic rather than targeted, spreading through outdated and vulnerable websites. Therefore, any user visiting one of these nearly 2,000 websites is a potential victim. Furthermore, due to the worm components that spread within a network after the initial infection, a single victim's computer could compromise an entire corporate or home network.

What You Can Do

Protecting against such a multi-layered threat requires precautions from both website administrators and end-users.

  • For WordPress Administrators: Always keep your website's core software, themes, and plugins up to date. Remove any plugins and themes you are not using. Use strong administrator passwords and enable two-factor authentication (2FA). Consider installing a security plugin that regularly checks the integrity of your website.
  • For End-Users: Be cautious of suspicious "Verification," "Update," or CAPTCHA prompts you encounter on websites. Do not trust pop-ups that ask you to download a file or run a command. Use a reputable antivirus software and ensure it is regularly updated. Regularly back up your important data to an external drive that is not connected to the internet or to a secure cloud service.

What The Company Says

Check Point, the firm that conducted the research, highlights the complexity and scale of the StopAndProtect operation. Jaromír Hořejší, one of the company's researchers, emphasized the multifaceted nature of the attack, stating, "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together." Check Point revealed that they were able to gain deep insights into the campaign due to the threat actor's operational security blunders. These mistakes exposed detailed infection logs from victim machines, screenshots, and the tools the attackers used to mass-manage the compromised websites. This information allowed researchers to map the internal workings and infrastructure of the attack.

Source

https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.