Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
StopAndProtect is a large-scale criminal operation abusing thousands of hacked WordPress websites to distribute malware and manage infected machines. The operation combines ransomware with data theft, using a multi-stage infection chain initiated by a social engineering ClickFix prompt that tricks victims into executing malicious PowerShell commands. The malware toolkit includes ransomware, worms, screen lockers, credential stealers, and chat utilities. The attackers use compromised WordPress sites as command-and-control servers and storage for stolen data and logs. Operational security failures exposed detailed logs and source code, revealing the scale and complexity of the campaign. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' infrastructure. The campaign affects victims globally, with many IPs from the US, Russia, and India.
AI Analysis
Technical Summary
StopAndProtect is a criminal operation identified in mid-2026 that leverages thousands of compromised WordPress websites as infrastructure for malware distribution, command and control, and data exfiltration. The infection begins with a social engineering technique involving a fake CAPTCHA ClickFix prompt that leads victims to execute a PowerShell command. This triggers a multi-stage infection involving .NET downloaders and loaders, deploying various malware components including ransomware, SMB/USB worms, LockScreen utilities, VBS spreaders, chat tools, and credential stealers. The operation collects telemetry and logs from infected machines, which are stored on hacked WordPress sites. Due to OPSEC failures, researchers accessed exposed directories containing logs, screenshots, and source code, revealing the operation's scale and tools. The attackers exploit outdated WordPress installations and vulnerable plugins, with some sites running versions from 2021 and containing multiple vulnerabilities such as SQL injection, authentication bypass, and arbitrary file uploads. The campaign is widespread, targeting thousands of IP addresses worldwide.
Potential Impact
The operation enables attackers to encrypt victim files (ransomware), steal sensitive documents and credentials, lock victim screens, and maintain persistent control via chat utilities. The abuse of thousands of compromised WordPress sites as infrastructure amplifies the attack's reach and resilience. Victims suffer data loss, potential credential compromise, and operational disruption. The exposure of attacker infrastructure and logs indicates a large-scale, coordinated campaign affecting diverse geographic regions. The exploitation of vulnerable WordPress sites also highlights risks to website owners who do not maintain timely updates and security patches.
Mitigation Recommendations
No official patch or fix is available for the StopAndProtect operation itself, as it is a criminal campaign leveraging compromised WordPress sites. Website owners should ensure their WordPress installations and plugins are kept up to date and secure to prevent compromise. Users should be cautious of social engineering prompts such as fake CAPTCHA ClickFix messages and avoid executing unsolicited PowerShell commands. Incident responders should investigate infections for multiple malware components and consider the possibility of data theft and ransomware. Monitoring for signs of compromise on WordPress infrastructure and removing unauthorized scripts is critical. Since the operation relies on hacked WordPress sites, securing and patching these sites is the primary mitigation step. Patch status is not yet confirmed for any specific vulnerabilities exploited; check vendor advisories for updates on WordPress and plugin security.
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Description
StopAndProtect is a large-scale criminal operation abusing thousands of hacked WordPress websites to distribute malware and manage infected machines. The operation combines ransomware with data theft, using a multi-stage infection chain initiated by a social engineering ClickFix prompt that tricks victims into executing malicious PowerShell commands. The malware toolkit includes ransomware, worms, screen lockers, credential stealers, and chat utilities. The attackers use compromised WordPress sites as command-and-control servers and storage for stolen data and logs. Operational security failures exposed detailed logs and source code, revealing the scale and complexity of the campaign. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' infrastructure. The campaign affects victims globally, with many IPs from the US, Russia, and India.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
StopAndProtect is a criminal operation identified in mid-2026 that leverages thousands of compromised WordPress websites as infrastructure for malware distribution, command and control, and data exfiltration. The infection begins with a social engineering technique involving a fake CAPTCHA ClickFix prompt that leads victims to execute a PowerShell command. This triggers a multi-stage infection involving .NET downloaders and loaders, deploying various malware components including ransomware, SMB/USB worms, LockScreen utilities, VBS spreaders, chat tools, and credential stealers. The operation collects telemetry and logs from infected machines, which are stored on hacked WordPress sites. Due to OPSEC failures, researchers accessed exposed directories containing logs, screenshots, and source code, revealing the operation's scale and tools. The attackers exploit outdated WordPress installations and vulnerable plugins, with some sites running versions from 2021 and containing multiple vulnerabilities such as SQL injection, authentication bypass, and arbitrary file uploads. The campaign is widespread, targeting thousands of IP addresses worldwide.
Potential Impact
The operation enables attackers to encrypt victim files (ransomware), steal sensitive documents and credentials, lock victim screens, and maintain persistent control via chat utilities. The abuse of thousands of compromised WordPress sites as infrastructure amplifies the attack's reach and resilience. Victims suffer data loss, potential credential compromise, and operational disruption. The exposure of attacker infrastructure and logs indicates a large-scale, coordinated campaign affecting diverse geographic regions. The exploitation of vulnerable WordPress sites also highlights risks to website owners who do not maintain timely updates and security patches.
Defensive Guidance
No official patch or fix is available for the StopAndProtect operation itself, as it is a criminal campaign leveraging compromised WordPress sites. Website owners should ensure their WordPress installations and plugins are kept up to date and secure to prevent compromise. Users should be cautious of social engineering prompts such as fake CAPTCHA ClickFix messages and avoid executing unsolicited PowerShell commands. Incident responders should investigate infections for multiple malware components and consider the possibility of data theft and ransomware. Monitoring for signs of compromise on WordPress infrastructure and removing unauthorized scripts is critical. Since the operation relies on hacked WordPress sites, securing and patching these sites is the primary mitigation step. Patch status is not yet confirmed for any specific vulnerabilities exploited; check vendor advisories for updates on WordPress and plugin security.
Technical Details
- Classification
- {"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","fetched":true,"fetchedAt":"2026-08-18T13:17:41.260Z","wordCount":3173}
Threat ID: 6a845b75c6e8be03323e7896
Added to database: 08/18/2026, 13:17:41 UTC
Last enriched: 08/18/2026, 13:17:54 UTC
Last updated: 08/18/2026, 13:27:34 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.