A server error by cybercriminals has revealed a global malware scheme called StopAndProtect, which utilized nearly 2,000 compromised WordPress sites to infect computers, steal files, and deploy ransomware. Check Point Research noted the ransomware component in May 2026 and discovered a complete malware toolkit being distributed via the hacked websites. Users who visited the infected sites were tricked into executing a PowerShell command under the pretense of completing a fake CAPTCHA, a method known as ClickFix.
StopAndProtect malware hits 2,000 hacked WordPress sites worldwide
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Fake CAPTCHA trick spreads ransomware via hacked WordPress sites
securityonline.info
-
StopAndProtect turns 2,000 hacked WordPress sites into malware hubs
securityaffairs.com
-
StopAndProtect malware hits 2,000 hacked WordPress sites worldwide
databreaches.net
-
StopAndProtect Campaign Hijacks 2,000 WordPress Sites for Malware
thehackernews.com
-
Hacked WordPress Sites Fuel StopAndProtect Malware Campaign
research.checkpoint.com