Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
StopAndProtect is a large-scale malware operation abusing thousands of hacked WordPress sites as infrastructure to spread malware, control infected machines, and store stolen data. It uses a multi-stage infection chain initiated by a social engineering ClickFix prompt leading to PowerShell scripts and .NET loaders. The operation includes ransomware, data theft, screen locking, credential stealing, and a chat utility. Operational security failures exposed extensive logs, screenshots, and source code, revealing the scale and tools used. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' control. The campaign affects victims globally, with many IPs from the US, Russia, and India. No official patch or fix is applicable as this is a malware campaign leveraging vulnerable third-party sites.
AI Analysis
Technical Summary
StopAndProtect is a multifaceted malware campaign first observed in May 2026 that leverages thousands of compromised WordPress websites as its operational infrastructure. The infection begins with a social engineering technique called ClickFix, prompting victims to execute a PowerShell command that triggers a multi-stage infection involving .NET downloaders and loaders. The malware toolkit includes ransomware, SMB/USB worms, lock screen components, VBS spreaders, chat utilities, and credential stealers. The attackers use hacked WordPress sites to host malware components, serve as command and control servers, and store exfiltrated victim data including logs and screenshots. Operational security lapses by the attackers exposed detailed infection logs and source code, revealing the scale of the campaign and nearly 2,000 compromised WordPress domains. Many of these sites are vulnerable due to outdated WordPress versions and plugins with multiple security flaws. The campaign targets victims worldwide, with a concentration of affected IPs in the US, Russia, and India.
Potential Impact
The operation results in widespread infection of victim machines with ransomware and data theft malware, leading to file encryption, exfiltration of sensitive documents, credential theft, and potential system lockout. The use of thousands of compromised WordPress sites as infrastructure amplifies the campaign's reach and persistence. Victims suffer data loss, privacy breaches, and operational disruption. The exposure of attacker operational data also provides insight into the campaign's scale and methods but does not mitigate the ongoing threat to victims.
Mitigation Recommendations
This is a malware campaign exploiting vulnerable WordPress sites rather than a software vulnerability with a patch. The primary mitigation is for WordPress site owners to keep their WordPress installations and plugins up to date to prevent compromise. Users should be cautious of social engineering prompts such as fake CAPTCHA ClickFix messages and avoid executing unsolicited PowerShell commands. Network defenders should monitor for indicators of compromise related to this campaign. No official patch or fix is available for the malware itself; remediation involves incident response and cleanup of infected systems and compromised websites.
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Description
StopAndProtect is a large-scale malware operation abusing thousands of hacked WordPress sites as infrastructure to spread malware, control infected machines, and store stolen data. It uses a multi-stage infection chain initiated by a social engineering ClickFix prompt leading to PowerShell scripts and .NET loaders. The operation includes ransomware, data theft, screen locking, credential stealing, and a chat utility. Operational security failures exposed extensive logs, screenshots, and source code, revealing the scale and tools used. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' control. The campaign affects victims globally, with many IPs from the US, Russia, and India. No official patch or fix is applicable as this is a malware campaign leveraging vulnerable third-party sites.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
StopAndProtect is a multifaceted malware campaign first observed in May 2026 that leverages thousands of compromised WordPress websites as its operational infrastructure. The infection begins with a social engineering technique called ClickFix, prompting victims to execute a PowerShell command that triggers a multi-stage infection involving .NET downloaders and loaders. The malware toolkit includes ransomware, SMB/USB worms, lock screen components, VBS spreaders, chat utilities, and credential stealers. The attackers use hacked WordPress sites to host malware components, serve as command and control servers, and store exfiltrated victim data including logs and screenshots. Operational security lapses by the attackers exposed detailed infection logs and source code, revealing the scale of the campaign and nearly 2,000 compromised WordPress domains. Many of these sites are vulnerable due to outdated WordPress versions and plugins with multiple security flaws. The campaign targets victims worldwide, with a concentration of affected IPs in the US, Russia, and India.
Potential Impact
The operation results in widespread infection of victim machines with ransomware and data theft malware, leading to file encryption, exfiltration of sensitive documents, credential theft, and potential system lockout. The use of thousands of compromised WordPress sites as infrastructure amplifies the campaign's reach and persistence. Victims suffer data loss, privacy breaches, and operational disruption. The exposure of attacker operational data also provides insight into the campaign's scale and methods but does not mitigate the ongoing threat to victims.
Defensive Guidance
This is a malware campaign exploiting vulnerable WordPress sites rather than a software vulnerability with a patch. The primary mitigation is for WordPress site owners to keep their WordPress installations and plugins up to date to prevent compromise. Users should be cautious of social engineering prompts such as fake CAPTCHA ClickFix messages and avoid executing unsolicited PowerShell commands. Network defenders should monitor for indicators of compromise related to this campaign. No official patch or fix is available for the malware itself; remediation involves incident response and cleanup of infected systems and compromised websites.
Technical Details
- Classification
- {"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","fetched":true,"fetchedAt":"2026-08-18T13:17:41.260Z","wordCount":3173}
Threat ID: 6a845b75c6e8be03323e7896
Added to database: 08/18/2026, 13:17:41 UTC
Last enriched: 09/11/2026, 21:47:27 UTC
Last updated: 10/01/2026, 10:04:27 UTC
Views: 108
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.