Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

0
High
Published: 08/18/2026 (08/18/2026, 13:05:44 UTC)
Source: Check Point Research

Description

StopAndProtect is a large-scale criminal operation abusing thousands of hacked WordPress websites to distribute malware and manage infected machines. The operation combines ransomware with data theft, using a multi-stage infection chain initiated by a social engineering ClickFix prompt that tricks victims into executing malicious PowerShell commands. The malware toolkit includes ransomware, worms, screen lockers, credential stealers, and chat utilities. The attackers use compromised WordPress sites as command-and-control servers and storage for stolen data and logs. Operational security failures exposed detailed logs and source code, revealing the scale and complexity of the campaign. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' infrastructure. The campaign affects victims globally, with many IPs from the US, Russia, and India.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 13:17:54 UTC

Technical Analysis

StopAndProtect is a criminal operation identified in mid-2026 that leverages thousands of compromised WordPress websites as infrastructure for malware distribution, command and control, and data exfiltration. The infection begins with a social engineering technique involving a fake CAPTCHA ClickFix prompt that leads victims to execute a PowerShell command. This triggers a multi-stage infection involving .NET downloaders and loaders, deploying various malware components including ransomware, SMB/USB worms, LockScreen utilities, VBS spreaders, chat tools, and credential stealers. The operation collects telemetry and logs from infected machines, which are stored on hacked WordPress sites. Due to OPSEC failures, researchers accessed exposed directories containing logs, screenshots, and source code, revealing the operation's scale and tools. The attackers exploit outdated WordPress installations and vulnerable plugins, with some sites running versions from 2021 and containing multiple vulnerabilities such as SQL injection, authentication bypass, and arbitrary file uploads. The campaign is widespread, targeting thousands of IP addresses worldwide.

Potential Impact

The operation enables attackers to encrypt victim files (ransomware), steal sensitive documents and credentials, lock victim screens, and maintain persistent control via chat utilities. The abuse of thousands of compromised WordPress sites as infrastructure amplifies the attack's reach and resilience. Victims suffer data loss, potential credential compromise, and operational disruption. The exposure of attacker infrastructure and logs indicates a large-scale, coordinated campaign affecting diverse geographic regions. The exploitation of vulnerable WordPress sites also highlights risks to website owners who do not maintain timely updates and security patches.

Defensive Guidance

No official patch or fix is available for the StopAndProtect operation itself, as it is a criminal campaign leveraging compromised WordPress sites. Website owners should ensure their WordPress installations and plugins are kept up to date and secure to prevent compromise. Users should be cautious of social engineering prompts such as fake CAPTCHA ClickFix messages and avoid executing unsolicited PowerShell commands. Incident responders should investigate infections for multiple malware components and consider the possibility of data theft and ransomware. Monitoring for signs of compromise on WordPress infrastructure and removing unauthorized scripts is critical. Since the operation relies on hacked WordPress sites, securing and patching these sites is the primary mitigation step. Patch status is not yet confirmed for any specific vulnerabilities exploited; check vendor advisories for updates on WordPress and plugin security.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","fetched":true,"fetchedAt":"2026-08-18T13:17:41.260Z","wordCount":3173}

Threat ID: 6a845b75c6e8be03323e7896

Added to database: 08/18/2026, 13:17:41 UTC

Last enriched: 08/18/2026, 13:17:54 UTC

Last updated: 08/18/2026, 13:27:34 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses