VMTech
Discuss a project

StopAndProtect Turns Hacked WordPress Sites Into Malware Infrastructure

StopAndProtect Turns Hacked WordPress Sites Into Malware Infrastructure

Check Point Research has identified a cybercrime operation dubbed StopAndProtect that uses nearly 2,000 compromised WordPress websites to distribute malware, issue command-and-control instructions and store data stolen from victims. The campaign, named after a ransomware family discovered in mid-May 2026, had compromised more than 6,000 unique IP addresses by July 24.

The operation begins with ClickFix social engineering. Visitors encounter counterfeit CAPTCHA-style prompts that instruct them to execute a PowerShell command. That command starts a multi-stage infection chain involving .NET downloaders and loaders before deploying a set of tools that can include ransomware, credential theft, data collection, lateral-movement utilities, a lock screen and a chat application.

A modular toolkit rather than ransomware alone

Check Point researcher Jaromír Hořejší described StopAndProtect as a toolkit of criminal software rather than a single malware strain. Its final stage contains SilentEncryptor, NetworkShareScanner, a VBS spreader, LockScreen, SimpleChatProxy and SilentDataCollector. SilentEncryptor can encrypt all infected computers or only hosts with specified names, while NetworkShareScanner spreads through SMB and USB media.

The VBS component can propagate through hard disks and removable media, scan networks and move laterally using WMI. SilentDataCollector builds an encrypted inventory of drives and sends it to the command-and-control server. Operators can place a command file on that server to direct the stealer to collect specific files.

Ransomware is not deployed in every observed intrusion. In many cases, the operators covertly gather file lists and selected files. Newer stealer versions add keylogging with valid-email detection, network-share mapping and unmapping, WhatsApp data collection, and screenshots captured every 30 seconds. Check Point said an operator can specify a WhatsApp search term, after which the malware automates searches in web or desktop WhatsApp and captures contact information as a screenshot.

Compromised WordPress sites support every stage

The infected WordPress estate hosts malware stages, acts as command-and-control infrastructure and keeps exfiltrated logs. Check Point found that many sites ran outdated WordPress versions and plugins. One compromised site used a WordPress release from 2021 and was exposed to roughly 40 vulnerabilities.

Attackers install a custom plugin through a ZIP archive containing uploader-installer.php. It creates a must-use plugin under wp-content/mu-plugins, enabling anyone with valid credentials to upload arbitrary files, including PHP files, to almost any path below the WordPress root. Such uploads can enable remote code execution. The plugin then deactivates and deletes itself to reduce the chance of discovery.

Investigators identified more than 700 stolen-data archives uploaded between mid-May and the end of July 2026. The archive set also included internal development material and a custom automation tool, fMain.frm, used to manage compromised WordPress pages at scale. The technique complements the broader pattern of attackers exploiting trusted web services, reflected in attacks on trusted web services and the operational risks created when legitimate-facing systems are taken over.

Business implications

Organizations operating WordPress sites should keep core software and plugins updated, review administrator access and inspect the must-use plugins directory for unauthorized files. Employees should leave any website that asks them to copy, paste or run commands outside the browser. These controls address both the compromised-site infrastructure and the ClickFix entry point used by StopAndProtect.

#cybersecurity#wordpress#malware#datatheft
Open analytics
On the site 2 views
min read 4 19.08.2026
Instagram

StopAndProtect Turns Hacked WordPress Sites Into Malware Infrastructure

Open the post on Instagram ↗