StopAndProtect Campaign Exploits Nearly 2,000 Hacked WordPress Sites for Malware Distribution

A global cybercrime operation known as StopAndProtect has been identified, utilizing thousands of compromised WordPress websites to spread malware and steal sensitive data.

A global cybercrime operation, dubbed StopAndProtect, has been flagged for exploiting nearly 2,000 hacked WordPress sites to disseminate malware and extract sensitive information. This operation employs a diverse toolkit of malicious software, enabling various functions such as file encryption, document theft, and user interface manipulation.

Operational Overview

According to cybersecurity researchers, the StopAndProtect campaign initiates with a ClickFix social engineering attack. This leads to the execution of a PowerShell command that deploys additional .NET downloaders and loaders, ultimately introducing the main malware components. These include ransomware, a worm that spreads via SMB/USB, a screen-locking utility, and a credential stealer.

Malware Functionality

The operation is characterized by its multi-faceted approach. While it often results in ransomware deployment, many instances involve the covert theft of files from compromised systems. The hacked WordPress sites serve multiple roles, including hosting malware, functioning as command-and-control (C2) servers, and storing logs from victim machines. Check Point Research noted that the attackers’ operational security lapses allowed for the exposure of detailed infection logs and screenshots from victim devices.

Vulnerabilities in WordPress Sites

Most of the compromised WordPress sites were found to be running outdated versions of the platform, making them susceptible to numerous vulnerabilities. For instance, one site was identified as operating a version from 2021, which is vulnerable to approximately 40 different security issues. The attackers manipulate these sites to present fake CAPTCHA prompts, further facilitating the infection process.

Data Exfiltration and Management

Investigations revealed that the threat actors utilize a ZIP archive containing a PHP file to install a custom WordPress plugin. This plugin enables unauthorized file uploads, including PHP files, which can lead to remote code execution. The campaign has resulted in the identification of over 700 archives containing stolen data from victim machines, including internal development files.

As of late July 2026, the campaign has affected more than 6,000 unique IP addresses, predominantly located in the U.S., Russia, and India. The findings underscore the potential for poorly maintained WordPress sites to be exploited as a distributed infrastructure for malware delivery and data theft.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 355