Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.
“The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims,” Check Point Research’s Jaromír Hořejší said.
The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026. The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders.
This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. That said, it’s worth noting that the operation does not always result in ransomware deployment. In most cases, the threat actors have been observed covertly stealing lists of files and then specific files from the systems.
The operation is supported by a cluster of hacked WordPress sites that serve multiple functions –
Host malware stages
Run as command-and-control (C2) servers to send instructions
Store logs exfiltrated from victims
Check Point said it was able to glean more insights into the campaign due to the threat actor’s operational security blunders that exposed detailed infection logs and screenshots from victim machines, as well as the tools used to mass-manage compromised websites. As many as close to 2,000 WordPress sites are estimated to have been hacked as part of the campaign.
Most of the sites have been found to not only run outdated versions of WordPress, but also installed plugins. One of the compromised websites, for instance, runs a WordPress version from 2021, making it susceptible to roughly 40 different vulnerabilities.
These sites are tampered with to serve fake ClickFix-style CAPTCHA prompts to visitors, effectively infecting themselves in the process. The PowerShell command triggered using this method acts as a conduit for a multi-step process –
A stage 1 .NET downloader that reports statistics to the C2 server and loads the next stage
A stage 2 .NET downloader and loader that incorporates sandbox checks and more logging mechanisms, and launches the main components
A stage 3 that includes six components:
SilentEncryptor, which encrypts either all currently infected computers or only computers with given host names
NetworkShareScanner, which functions like an SMB/USB worm to spread to other devices
VBS spreader, which propagates the malware to hard disks and removable media, scans the network, and laterally moves via WMI
LockScreen, which blocks user input and displays a ransom message with a payment QR code)
SimpleChatProxy, which is a custom chat application for communicating between the victim and operator
SilentDataCollector, which generates a list of all drives, encrypts it, and exfiltrates this list to the C2 server. The operator can upload a command file to the server that the stealer reads to harvest specific files.
Newer iterations of the stealer also implement extra features, including a keylogger with valid email address detection, exfiltration from WhatsApp, mapping and unmapping network shares, and capturing screenshots of user activity every 30 seconds.
“An operator may issue a WhatsApp search keyword; both the web and desktop versions are supported,” Check Point said. “The stealer waits until the victim becomes inactive and then uses WhatsApp automation to focus the search box, enter the specified keyword (contact name), open the contact information, and capture a screenshot.”
Further investigation has determined that the threat actors make use of a ZIP archive containing a PHP file (“uploader-installer.php”) to install a custom WordPress plugin, which is used to create a must-use (MU) plugin file that’s responsible for creating a must-use (MU) plugin file in the “wp-content/mu-plugins” directory.
The plugin lets anyone in possession of valid credentials upload arbitrary files, including PHP files, to the WordPress site to almost any path under the WordPress root. The upload of PHP files can pave the way for remote code execution. Once the site has been interfered with, the plugin deactivates itself and self-deletes to sidestep detection.
The uploaded files include stolen data from victim machines, with more than 700 archives identified from mid-May to the end of July 2026. Among those files are internal development files and tools in what appears to be a case of the operator inadvertently infecting themselves. This includes a custom automation utility named “fMain.frm” that’s used to manage compromised WordPress sites.
“This automation tool allows the botnet operator to mass-manage compromised WordPress pages,” Check Point said. “It uses secure upload and delete PHP scripts on compromised websites to upload or delete additional files, activate or deactivate fake-captcha ClickFix, activate or deactivate caching, etc.”
The compromised sites contain a malicious “verify” plugin that overlays the original content with a fake CAPTCHA for non-Windows visitors. The plugin is activated after the threat actor uploads a file called “activator.php,” after which it deletes itself.
As of July 24, 2026, the campaign has compromised more than 6,000 unique IP addresses. Most of them are located in the U.S. (1,852), Russia (630), and India (630).
“StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware,” Check Point’s Eli Smadja said.
“We urge organizations to be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser.”
📰 Original Source:TheHackerNews ✍️ Author: info@thehackernews.com (The Hacker News)
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Leave a Reply