The StopAndProtect campaign turned compromised WordPress websites into infrastructure for malware distribution, command-and-control operations and data theft, exposing visitors and highlighting the risks of outdated software and plugins.
Nearly 2,000 WordPress websites were compromised as part of the StopAndProtect cybercrime operation, with attackers using legitimate sites to distribute malware, steal information and control infected systems, according to Check Point Research.
The cybersecurity company uncovered the campaign in May 2026 while investigating a ransomware strain. Its analysis found that compromised WordPress websites had been incorporated into a broader attack infrastructure rather than being targeted solely for their own data.
The hacked sites served multiple purposes, including hosting malware, communicating with infected devices and storing information stolen from victims. This approach allowed attackers to use trusted websites instead of building their own infrastructure from scratch.
Ranjeeth Bellary, Partner, Forensic and Integrity Services – Cyber Forensics at EY, said the widespread use of WordPress makes it attractive to cybercriminals.
“WordPress is enormously widespread, and therefore attackers do not necessarily need to build their own infrastructure. They can compromise legitimate sites and effectively "rent" the website's existing reputation, domain age, hosting environment and normal user traffic.”
Outdated WordPress versions create entry points
Check Point said many of the compromised websites were running outdated WordPress versions or vulnerable plugins. In one case, researchers found a website using a WordPress release dating back to 2021, with almost 40 known vulnerabilities.
The flaws identified included SQL injection, open redirects, authentication bypasses and unauthorised file uploads. Once attackers gained access, they could use the websites as malware delivery points, command-and-control servers and repositories for stolen information.
Bellary said the distributed nature of the infrastructure can make such campaigns harder to disrupt.
“A distributed network of compromised websites is harder to disrupt than one centrally hosted malicious server. A legitimate WordPress site can become a malware distribution point, command-and-control layer and even a repository for stolen data. Attackers get scale and legitimacy without having to build that infrastructure themselves.”
The campaign also demonstrated how website visitors could become unintended victims. People accessing compromised sites could encounter malicious content even if they were not the original targets of the attack.
Fake CAPTCHA becomes a malware trap
Attackers also modified some compromised websites to display fake CAPTCHA verification pages. Instead of simply checking whether visitors were human, these pages were used as part of a ClickFix-style social-engineering attack.
The technique attempts to persuade users to perform seemingly routine actions. In the observed campaign, a fake CAPTCHA could place a PowerShell command in the user's clipboard and then encourage the victim to execute it.
Bellary said attackers were exploiting people's familiarity with CAPTCHA and “verify you are human” prompts.
“In the ClickFix technique observed in these campaigns, the victim is told to perform an apparently harmless action such as "verify you are human", but the process causes a malicious command to be copied and then asks the victim to execute it.”
He described the method as psychological manipulation rather than a technically complicated attack. By imitating familiar security checks, criminals can persuade users to complete the final stage of an infection themselves.
The malware ecosystem uncovered by Check Point was also diverse. Researchers identified components capable of encrypting files, displaying ransom messages, scanning network shares and removable devices, and spreading across connected systems.
Other malware tools were designed for data theft. They could identify files on infected machines and send information to attackers, who could then select specific files for collection. Later versions reportedly added capabilities such as keylogging, WhatsApp contact searches, network mapping and screenshot capture.
Exposed infrastructure reveals campaign scale
Check Point's investigation found more than 6,000 unique IP addresses associated with the campaign as of July 26. The US accounted for 1,852 addresses, while Russia and India each recorded 630.
Researchers cautioned that the figures could include security researchers and sandbox environments, although most addresses appeared to represent infected machines.
The investigation also uncovered exposed directories containing victim information. Check Point said it collected around 31,000 screenshots between mid-May and the end of July. More than 700 archives containing stolen data were also discovered, including files, password-related information, cryptocurrency wallet data and encryption logs.
In an unusual development, researchers found files that appeared to belong to the attackers themselves. The material included tools used to manage compromised WordPress websites, including capabilities to upload and delete files and activate or disable fake CAPTCHA pages.
The campaign underscores the importance of maintaining website security. Experts recommend keeping WordPress, plugins and themes updated, removing unsupported or unused components, strengthening administrator access and monitoring websites for unauthorised changes.
Website owners should also consider web application firewalls, malware monitoring and regularly tested backups. These measures can help detect compromises earlier, limit the spread of malicious activity and support faster recovery after an attack.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




