Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims," Check Point Research's Jaromír Hořejší said. The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026. The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders. This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. That said, it's worth noting that the operation does not always result in ransomware deployment. In most cases, the threat actors have been observed covertly stealing lists of files and then specific files from the systems. The operation is supported by a cluster of hacked WordPress sites that serve multiple functions - - Host malware stages - Run as command-and-control (C2) servers to send instructions - Store logs exfiltrated from victims Check Point said it was able to glean more insights into the campaign due to the threat actor's operational security blunders that exposed detailed infection logs and screenshots from victim machines, as well as the tools used to mass-manage compromised websites. As many as close to 2,000 WordPress sites are estimated to have been hacked as part of the campaign. Most of the sites
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Read the original article
thehackernews.com →