StopAndProtect Hijacks 2,000 WordPress Sites
A large-scale cybercrime campaign dubbed StopAndProtect is exploiting nearly 2,000 compromised WordPress websites to distribute malware, control infected systems and store information stolen from victims.
According to Check Point Research, StopAndProtect is not built around a single malware strain. Instead, attackers are operating a multi-component criminal toolkit capable of encrypting files, stealing documents and credentials, locking screens, spreading across systems and even communicating directly with victims.
The infection begins with a ClickFix social-engineering attack, which tricks users into executing a PowerShell command. This triggers additional .NET downloaders and loaders that install various malicious components, including ransomware, credential stealers, SMB/USB worms, VBS spreaders and screen-locking malware.
Interestingly, ransomware is not always the attackers' primary objective. In many observed cases, the criminals operate quietly, first collecting lists of files and then exfiltrating selected documents, screenshots and system information.
A defining feature of StopAndProtect is its abuse of compromised WordPress websites. Rather than simply attacking website owners, criminals turn these sites into distributed infrastructure for hosting malware, command-and-control communications and storing stolen information.
Check Point researchers gained unusual visibility into the operation because mistakes by the attackers reportedly exposed infection logs, screenshots from compromised machines and tools used to manage large numbers of hacked websites.
Many affected sites were running outdated WordPress installations and vulnerable plugins. One compromised website reportedly used a WordPress version dating from 2021 and was potentially exposed to around 40 known vulnerabilities.
StopAndProtect demonstrates how unpatched internet infrastructure can become a force multiplier for cybercrime. A vulnerable WordPress website may appear insignificant individually, but thousands of compromised sites can collectively form a resilient malware-distribution and command infrastructure.
The campaign also reinforces why organizations cannot focus only on protecting endpoints. Websites, plugins, content-management systems and forgotten internet-facing assets must be continuously inventoried, patched and monitored.
The larger lesson is simple: today's unpatched website can become tomorrow's cybercriminal infrastructure.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




