A cybercrime operation known as StopAndProtect has leveraged nearly 2,000 compromised WordPress websites to distribute malware, siphon cryptocurrency wallet files, and deploy ransomware. According to a report published by Check Point Research on August 18, the campaign was first identified in mid-May 2026 and has grown into a major web-infrastructure hijacking scheme.
The campaign has infected over 6,000 unique IP addresses by using a social-engineering tactic called ClickFix. Visitors to the compromised WordPress sites are presented with fake CAPTCHA verification prompts that trick them into executing malicious PowerShell commands on their personal computers.
The initial PowerShell command downloads a .NET loader, which subsequently installs a suite of malware components including credential stealers, antivirus-evasion tools, and specialized modules designed to locate and exfiltrate cryptocurrency wallet files. The hijacked WordPress sites serve a dual purpose, acting as both the initial distribution bait and as command-and-control servers or data storage repositories. Many of the targeted sites were running WordPress versions dating back to 2021.
Geographically, the campaign has affected users across multiple regions. Out of more than 6,000 unique IP addresses flagged by July 24, the United States accounted for 1,852 addresses, while Russia and India recorded 630 addresses each.
Check Point researchers gained access to more than 31,000 victim screenshots and directories containing up to 700 stolen data archives, revealing the scope of the harvested data. Unlike standard ransomware operations, StopAndProtect combines selective file encryption with extensive data theft and user surveillance, creating a continuous stream of stolen credentials, wallet files, and screenshots.
The explicit targeting of cryptocurrency wallet files poses a direct risk to digital asset holders who store private keys or seed phrases on devices that may visit compromised web pages. Researchers note that basic patch management and updates for outdated WordPress installations could have prevented a significant portion of the infrastructure from being compromised.


