Hackers Turn Thousands of Compromised WordPress Sites Into C2 Servers for StopAndProtect Malware

A newly uncovered malware operation dubbed StopAndProtect is remodeling hundreds of hacked WordPress web sites right into a sprawling felony command-and-control (C2) infrastructure.

The marketing campaign blends double-extortion ransomware with covert information theft, quietly harvesting delicate company paperwork, system screenshots, person credentials, and lively communication logs from compromised machines worldwide.

Inner logs uncovered by way of the menace actors’ operational safety failures reveal over 6,000 distinctive sufferer IP addresses throughout the globe, with the best an infection charges concentrated in the USA, Russia, and India.

The operators actively handle near 2,000 compromised WordPress domains, making a resilient, rotating pool of infrastructure to distribute payloads, preserve management channels, and retailer exfiltrated recordsdata.

Hackers Flip WordPress Websites Into C2 Servers

The preliminary compromise vector depends on misleading fake CAPTCHA lures injected straight into weak WordPress web sites.

When guests land on compromised pages, they’re introduced with a fraudulent human-verification immediate instructing them to repeat and paste a malicious PowerShell command into their terminal.

An infection chain (Picture Supply: checkpoint.com)

As soon as executed, the command initiates a multi-stage an infection sequence pushed by twin PowerShell scripts and modular .NET loaders, in the end deploying a flexible toolkit that features ransomware, credential stealers, display screen lockers, VBS spreaders, and USB community worms.

As detailed within the investigative report published by Check Point Research, the operation departs from standard smash-and-grab assaults by prioritizing intelligence gathering and selective monetization.

Menace actors conduct intensive doc enumeration, log keystrokes, map related community shares, seize periodic screenshots, and scrape native communication information earlier than deciding whether or not to deploy ransomware.

Screenshot of WhatsApp contact details exfiltrated by the stealer
Screenshot of WhatsApp contact particulars exfiltrated by the stealer (Picture Supply: checkpoint.com)

A number of compromised WordPress staging servers left uncovered PHP endpoints and open listing listings accessible to the general public, permitting safety researchers to examine inner exercise logs, sufferer telemetry, and uncooked supply code.

In a single notable occasion, the operator apparently contaminated their private machine and inadvertently uploaded inner improvement recordsdata, together with a customized Visible Fundamental 6 software used to mass-manage hijacked WordPress domains, toggle pretend CAPTCHA overlays, and deploy new payloads throughout the botnet.

The marketing campaign highlights the extreme dangers of unmaintained Content material Administration Methods. One analyzed web site had been working with out updates since 2021, exposing almost 40 unpatched vulnerabilities.

Unaddressed WordPress security flaws and outdated plugins present adversaries with persistent backdoors to transform respectable web sites into malicious relays.

Addressing these compromised endpoints is significant to disrupting trendy ransomware deployment tactics earlier than adversaries transfer laterally throughout inner networks.

Compromised web sites are not serving solely as easy phishing hosts or visitors redirectors; they’re now weaponized as absolutely purposeful C2 servers that mix malicious communications with respectable net visitors.

Web site directors should implement rigorous replace schedules throughout WordPress core recordsdata, lively themes, and third-party plugins whereas usually scanning for unauthorized PHP scripts, modified .htaccess recordsdata, and suspicious administrator accounts.

Finish customers ought to deal with any web site prompting terminal command execution as a direct compromise try, and safety groups should monitor endpoint telemetry for unauthorized PowerShell execution and anomalous outbound information transfers.

IOCs

compromised web sites maximumrock[.]ro
platinumcar[.]ca
norakremer.co[.]uk
pharmart[.]ae
ksr-racingparts[.]com
compromised base C&C web sites v-k.com[.]ua
www.lapellelaser[.]pl
www.parsrulman[.]com
mectcalcutta[.]com
discherniation[.]com
PowerShell script stage 1 cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0
PowerShell script stage 2 cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9
stage 1 – downloader 99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b
8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5
4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504
stage 2 – downloader & loader 9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527
7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c
976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153
stage 3 – encryptor b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489
65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143
0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40
stage 3 – SMB/USB worm 8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4
10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0
f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41
stage 3 – lockscreen 11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e
2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c
38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9
stage 3 – credential stealer 23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70
stage 3 – VBS spreader b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad
stage 3 – chat utility 3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9
3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8

Ā Strengthen Your SOC by Accelerating Menace Detection & Speedy Investigations.Ā ->Ā Integrate ANY.RUN With Your SOCĀ Now.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *