All incidents

StopAndProtect malware campaign hijacks 2,000 WordPress sites

malwareopenAug 18, 2026 — Aug 19, 2026
StopAndProtect malware campaign hijacks 2,000 WordPress sites

CYBERSECURITY researchers have uncovered a malware campaign dubbed StopAndProtect that has hijacked close to two thousand WordPress sites to spread ransomware and steal data according to a report on databreaches.net. The operation was exposed after a misconfigured server left infection logs and screenshots publicly accessible.

Visitors to the compromised pages are presented with a fake CAPTCHA that urges them to run a PowerShell command, a technique known as ClickFix as detailed by The Hacker News. That command launches a chain of scripts that deploy a ransomware module, harvest credentials and maintain communication with attacker controlled servers.

The underlying weakness stems from outdated WordPress installations that allow attackers to install malicious plugins or modify core files. Check Point Research noted that the campaign primarily affected victims in the United States, Russia and India, based on the exposed logs as outlined in their analysis.

Although no specific threat actor has been linked to the effort, the malware has been active since mid August 2026 and continues to infect new hosts. The public exposure of the command and control infrastructure suggests the operation may be winding down or shifting tactics.

The incident highlights how attackers abuse legitimate web platforms to launch large scale attacks with relatively low effort. It also shows the danger of relying on outdated content management systems without regular patching.

Site administrators should immediately update WordPress core, themes and plugins to the latest versions and remove any unfamiliar extensions. They should also review file integrity and look for unexpected scripts or scheduled tasks that could indicate a compromise.

Network defenders ought to block outbound PowerShell execution from workstations unless explicitly required and monitor for the fake CAPTCHA lure in web traffic. Educating users about the risks of clicking on unknown prompts and enforcing least privilege on accounts can reduce the chance of successful infection.

Intelligence briefing updated Aug 19, 2026

Timeline Coverage

Swipe to explore timeline