securityaffairs.com 8/20/2026, 8:11:10 AM · external

StopAndProtect turns 2,000 hacked WordPress sites into malware hubs

StopAndProtect turns 2,000 hacked WordPress sites into malware hubs
Developing story malware 4 articles tracked
StopAndProtect campaign hijacks 2,000 WordPress sites for malware distribution
CyberSIXT Evidence Panel

STOPANDPROTECT is a cybercrime operation identified by Check Point Research that has transformed nearly 2,000 hacked WordPress websites into a platform for malware distribution, data theft, and ransomware. The operation began in May 2026 and uses a deceptive CAPTCHA technique to lure visitors into executing a PowerShell command, subsequently downloading malware. This malware serves multiple purposes: encrypting files, stealing documents, providing a communication channel for attackers, and even spying on victims.

The compromised websites often utilized outdated WordPress versions, confirming the need for site security through regular updates and strong protections. Researchers discovered extensive amounts of victim data collected during the operation, leading to significant concerns over personal privacy and cybersecurity.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline