Ethical Hacking News
A malicious network of hacked WordPress sites has turned into a criminal platform for malware delivery, data theft, surveillance, and ransomware. StopAndProtect, a sophisticated cybercrime operation, combines file encryption with data theft, using thousands of hacked WordPress sites as its infrastructure. This network has collected a remarkable amount of victim information, including stolen files, passwords, wallet information, screenshots, and activity logs. The campaign moves beyond file encryption, becoming a surveillance operation with a ransomware component attached. To protect yourself, update your WordPress and plugins, protect administrative accounts, and review installed plugins. Be cautious of fake CAPTCHAs and do not run instructions on your computer.
A malicious network called StopAndProtect has compromised nearly 2,000 WordPress sites to deliver malware, steal data, and conduct surveillance. The operation uses a fake CAPTCHA to spread malware, which unfolds through multiple downloaders and loaders before deploying different malware components. The malware toolkit can encrypt files, steal documents, lock screens, and provide attackers with a chat channel to communicate with victims. The campaign has reached over 2,000 compromised WordPress domains, with hackers using them for multiple jobs at once, including hosting malware stages and storing stolen files. The infection chain is straightforward, with visitors running PowerShell and downloading malware, which can then encrypt files, spread through SMB shares and USB devices, and steal credentials. The operators have built tools to manage the infected websites at scale, including an automation utility that can upload and delete files, enable or disable fake CAPTCHA pages, and manage additional payloads. The campaign has collected a significant amount of victim information, including stolen files, passwords, wallet information, screenshots, and activity logs. The malware can also monitor WhatsApp activity, search for a contact name, and capture the person's details, including a phone number. Webmasters can protect their sites by updating WordPress and plugins, removing unsupported software, and using strong passwords and multi-factor authentication. Visitors should be cautious of CAPTCHAs that ask them to run PowerShell or disable security controls, and should close any suspicious browser prompts.
The dark web is often associated with illicit activities, and one of the most insidious creations to emerge from this realm is StopAndProtect, a malicious network of hacked WordPress sites turned criminal platform. This network, created by a group of skilled hackers, has managed to turn nearly 2,000 compromised WordPress websites into a shared infrastructure for malware delivery, data theft, surveillance, and ransomware.
According to a recent report by Check Point Research, StopAndProtect is a sophisticated cybercrime operation that combines file encryption with data theft. The hackers use thousands of hacked WordPress sites as their infrastructure, abusing them to spread malware, control infected machines, and store stolen documents, screenshots, and activity logs. The operation starts with a fake CAPTCHA based on the ClickFix technique, which prompts visitors to prove they're human, but the instructions actually push them into copying and running a PowerShell command.
From there, the infection unfolds through several downloaders and loaders before deploying different malware components. StopAndProtect uses a toolkit of different malware rather than a single strain, which can encrypt files, steal documents, lock screens, and even provide attackers with a chat channel to communicate with victims. This malware can also monitor WhatsApp activity, search for a contact name, and capture the person's details, including a phone number.
The campaign appears to have reached close to 2,000 compromised WordPress domains, many of which were running old versions of WordPress or outdated plugins. The hackers used compromised WordPress sites for several jobs at once, hosting malware stages, delivering commands, receiving logs, and storing stolen files. Check Point discovered this because one of the servers exposed a directory listing through a PHP script, revealing more files, logs, and open folders than the operators probably intended.
The infection chain is straightforward enough to understand, even if it becomes more complex after the first step. A visitor sees a fake CAPTCHA, follows the instructions, runs PowerShell, and downloads further stages written in .NET. The malware can then encrypt files, spread through SMB shares and USB devices, steal credentials, capture screenshots, collect selected documents or show a ransom message.
The operators also built tools to manage the infected websites at scale. Check Point found an automation utility that could upload and delete files, enable or disable fake CAPTCHA pages, change redirects, and manage additional payloads across the compromised sites. This utility was written with Visual Basic 6, a technology old enough to have a pension plan, but apparently still useful when the job is mass-managing hacked servers.
The campaign collected a remarkable amount of victim information. From mid-May to the end of July 2026, researchers found more than 700 archives containing stolen files, passwords, wallet information, screenshots, and activity logs. One exposed directory held more than 20,000 screenshot files, while the researchers collected roughly 31,000 screenshots during the monitoring period.
Some of the captured images showed victims' desktops, browser activity, antivirus windows, ransom messages, and lists of encrypted files. The malware could also monitor WhatsApp activity, search for a contact name, and capture the person's details, including a phone number. This moves the campaign well beyond file encryption: it becomes a surveillance operation with a ransomware component attached.
Check Point counted more than 6,000 unique IP addresses associated with the campaign by 24 July 2026. The largest groups came from the United States, Russia, and India, although IP location does not necessarily identify the victims' real location or the operators behind the operation.
For website owners, the basic response is still the right one: update WordPress and every plugin, remove anything unsupported, protect administrative accounts with strong passwords and multi-factor authentication, review installed plugins, and check for unexpected PHP files or unfamiliar administrator accounts. Web server logs, outbound connections, and recent file changes deserve particular attention if a site may have been compromised.
For visitors, the warning is more specific. A CAPTCHA should not ask someone to open PowerShell, paste a command into a terminal, or disable security controls. If a webpage tells you to leave the browser and run instructions on your computer, close it. The CAPTCHA isn't testing whether you're human; it's testing whether you'll do the attacker's work for them.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Dark-Webs-Most-Sinister-Creation-StopAndProtect-a-Malicious-Network-of-Hacked-WordPress-Sites-ehn.shtml
https://securityaffairs.com/197537/hacking/stopandprotect-turns-2000-hacked-wordpress-sites-into-a-criminal-network.html
https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html
Published: Thu Aug 20 03:51:19 2026 by llama3.2 3B Q4_K_M