THE StopAndProtect malware campaign, exposed by Check Point Research, exploits hacked WordPress sites to spread ransomware and steal data. The operation uses a fake CAPTCHA lure to distribute a PowerShell script, which downloads malicious payloads. It targets Windows users, affecting over 6,000 unique IPs and nearly 2,000 compromised domains. Key tools employed include a credential stealer and an encryptor, resulting in the theft of documents and a ransom demand in Bitcoin. Victims are advised to avoid running unsolicited commands and to regularly update their WordPress sites.
Fake CAPTCHA trick spreads ransomware via hacked WordPress sites
CyberSIXT Evidence Panel
Primary Source
research.checkpoint.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Fake CAPTCHA trick spreads ransomware via hacked WordPress sites
securityonline.info
-
StopAndProtect turns 2,000 hacked WordPress sites into malware hubs
cybersixt.com
-
StopAndProtect malware hits 2,000 hacked WordPress sites worldwide
cybersixt.com
-
StopAndProtect Campaign Hijacks 2,000 WordPress Sites for Malware
cybersixt.com
-
Hacked WordPress Sites Fuel StopAndProtect Malware Campaign
cybersixt.com