Published on August 23, 2026

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data


Severity

Medium

Detail

StopAndProtect is a large-scale cybercrime campaign that has compromised thousands of vulnerable WordPress websites to distribute malware, steal data, and support ransomware operations. The campaign primarily targets Windows users through fake CAPTCHA pages and ClickFix social engineering.

How?

The attack begins with threat actors compromising vulnerable WordPress websites, many of which are running outdated WordPress versions and plugins. The attackers install a malicious plugin that gives them the ability to upload files, manage website content, and activate fake CAPTCHA pages. These compromised websites are also used as malware hosting and command-and-control (C2) infrastructure.

When a Windows user visits an affected website, the malicious plugin displays a fake CAPTCHA verification page. Instead of completing a normal CAPTCHA, the victim is instructed to copy and execute a PowerShell command. This ClickFix technique starts a multi-stage infection that downloads .NET-based loaders onto the victim’s system.

The first-stage downloader contacts the attackers’ infrastructure and retrieves the next component. A second-stage loader performs additional checks, including sandbox detection, before deploying the main malware components. These can include SilentEncryptor, NetworkShareScanner, a VBS spreader, LockScreen, SimpleChatProxy, and SilentDataCollector.

The malware can then collect file listings and specific documents, capture screenshots, record keystrokes, and steal information from applications such as WhatsApp. Other components allow the attackers to spread across network shares, removable drives, and other systems through WMI. If the attackers choose to conduct a ransomware attack, the encryption component can lock files and the LockScreen component can display a ransom message.

Stolen information is uploaded to other compromised WordPress websites, allowing the attackers to use the same infrastructure for both malware delivery and data storage. The campaign operators can remotely manage these websites, activate or deactivate the fake CAPTCHA, upload additional malware, and delete files to reduce evidence of their activity.

Conclusion

StopAndProtect demonstrates how vulnerable WordPress websites can be transformed into distributed infrastructure for malware delivery, data theft, lateral movement, and ransomware. Organizations should keep WordPress and plugins updated, monitor for unauthorized website changes, and educate users to avoid CAPTCHA pages that instruct them to copy and execute commands.

Source

https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html