Skip to main content

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

0
High
Published: 08/18/2026 (08/18/2026, 13:05:44 UTC)
Source: Check Point Research

Description

StopAndProtect is a large-scale malware operation abusing thousands of hacked WordPress sites as infrastructure to spread malware, control infected machines, and store stolen data. It uses a multi-stage infection chain initiated by a social engineering ClickFix prompt leading to PowerShell scripts and .NET loaders. The operation includes ransomware, data theft, screen locking, credential stealing, and a chat utility. Operational security failures exposed extensive logs, screenshots, and source code, revealing the scale and tools used. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' control. The campaign affects victims globally, with many IPs from the US, Russia, and India. No official patch or fix is applicable as this is a malware campaign leveraging vulnerable third-party sites.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 21:47:27 UTC

Technical Analysis

StopAndProtect is a multifaceted malware campaign first observed in May 2026 that leverages thousands of compromised WordPress websites as its operational infrastructure. The infection begins with a social engineering technique called ClickFix, prompting victims to execute a PowerShell command that triggers a multi-stage infection involving .NET downloaders and loaders. The malware toolkit includes ransomware, SMB/USB worms, lock screen components, VBS spreaders, chat utilities, and credential stealers. The attackers use hacked WordPress sites to host malware components, serve as command and control servers, and store exfiltrated victim data including logs and screenshots. Operational security lapses by the attackers exposed detailed infection logs and source code, revealing the scale of the campaign and nearly 2,000 compromised WordPress domains. Many of these sites are vulnerable due to outdated WordPress versions and plugins with multiple security flaws. The campaign targets victims worldwide, with a concentration of affected IPs in the US, Russia, and India.

Potential Impact

The operation results in widespread infection of victim machines with ransomware and data theft malware, leading to file encryption, exfiltration of sensitive documents, credential theft, and potential system lockout. The use of thousands of compromised WordPress sites as infrastructure amplifies the campaign's reach and persistence. Victims suffer data loss, privacy breaches, and operational disruption. The exposure of attacker operational data also provides insight into the campaign's scale and methods but does not mitigate the ongoing threat to victims.

Defensive Guidance

This is a malware campaign exploiting vulnerable WordPress sites rather than a software vulnerability with a patch. The primary mitigation is for WordPress site owners to keep their WordPress installations and plugins up to date to prevent compromise. Users should be cautious of social engineering prompts such as fake CAPTCHA ClickFix messages and avoid executing unsolicited PowerShell commands. Network defenders should monitor for indicators of compromise related to this campaign. No official patch or fix is available for the malware itself; remediation involves incident response and cleanup of infected systems and compromised websites.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","fetched":true,"fetchedAt":"2026-08-18T13:17:41.260Z","wordCount":3173}

Threat ID: 6a845b75c6e8be03323e7896

Added to database: 08/18/2026, 13:17:41 UTC

Last enriched: 09/11/2026, 21:47:27 UTC

Last updated: 10/01/2026, 10:04:27 UTC

Views: 108

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses