securityonline.info 8/24/2026, 7:51:18 AM · external

Fake CAPTCHA trick spreads ransomware via hacked WordPress sites

Fake CAPTCHA trick spreads ransomware via hacked WordPress sites
Developing story malware 5 articles tracked
StopAndProtect malware campaign hijacks thousands of WordPress sites
CyberSIXT Evidence Panel

THE StopAndProtect malware campaign, exposed by Check Point Research, exploits hacked WordPress sites to spread ransomware and steal data. The operation uses a fake CAPTCHA lure to distribute a PowerShell script, which downloads malicious payloads. It targets Windows users, affecting over 6,000 unique IPs and nearly 2,000 compromised domains. Key tools employed include a credential stealer and an encryptor, resulting in the theft of documents and a ransom demand in Bitcoin. Victims are advised to avoid running unsolicited commands and to regularly update their WordPress sites.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline