A report published by Check Point Research reveals that nearly 2,000 hacked WordPress websites have been utilized to build a criminal infrastructure for distributing malware, stealing data, monitoring victims, and deploying ransomware.
According to the cybersecurity firm, the StopAndProtect ransomware family was first discovered in mid-May. The compromised websites served multiple functions within the operation, including hosting malware, transmitting commands to infected machines, and storing stolen documents, screenshots, and activity logs.
Check Point researcher JaromÃr Horejsi noted that the operation relies on a toolkit of criminal software. Components include file encryptors, silent document stealers, screen lockers, and a live chat interface between attackers and their victims.
The Windows-targeting malware campaign typically begins with a fake CAPTCHA prompt on a compromised website. This ClickFix prompt instructs visitors to run a PowerShell command that installs malware capable of stealing credentials and cryptocurrency wallet seed phrases, locking screens, and deploying ransomware.
Operational security failures by the attackers allowed researchers to gain deeper visibility into the operation. Exposed directories contained detailed infection logs, screenshots, and the source code of tools used to manage the compromised sites. By July 24, the campaign had compromised more than 6,000 unique IP addresses, with 1,852 in the United States and 630 each in Russia and India.
Between mid-May and the end of July, researchers collected over 31,000 screenshots and more than 700 archives containing stolen data, such as documents, passwords, and cryptocurrency wallet files. Furthermore, researchers believe the threat actors accidentally infected themselves, as an exfiltrated archive contained unusual files with suspicious content that offered additional insight into the operation.


