research.checkpoint.com 8/18/2026, 1:41:29 PM · external

Hacked WordPress Sites Fuel StopAndProtect Malware Campaign

Hacked WordPress Sites Fuel StopAndProtect Malware Campaign
CyberSIXT Evidence Panel Source marked as original reporting

THE report discusses the StopAndProtect operation, which utilizes a network of hacked WordPress sites to distribute malware, engage in data theft, and implement ransomware. Key findings include extensive operational security failures leading to the exposure of infection logs and screenshots from infected machines, revealing a large-scale campaign affecting thousands of victims predominantly in the US, Russia, and India.

The infection chain begins with social engineering through a ClickFix prompt that triggers a sequence of PowerShell scripts and various payloads, including a ransomware component and tools for credential theft and communication with victims. The report highlights the attackers' carelessness and the vulnerabilities in outdated WordPress installations that facilitate the operation, with over 31,000 screenshots collected from victims during the investigation. Overall, the analysis emphasizes the scale and sophistication of the threat posed by this operation.

View full article

Article by CyberSIXT