StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a world cybercrime operation that abuses hundreds of hacked WordPress web sites as infrastructure to disseminate malware, commandeer contaminated hosts, retailer stolen paperwork, screenshots, and exercise logs created to trace the standing of the exercise.

“The operation would not depend on a single piece of malware, however on an entire toolkit of felony software program working collectively – some elements encrypt information, others silently steal paperwork or lock the display screen, and one other acts as a stay chat between the attackers and their victims,” Test Level Analysis’s Jaromír Hořejší said.

The big-scale marketing campaign is being tracked by the cybersecurity firm underneath the moniker StopAndProtect after discovering a ransomware household of the identical identify in mid-Might 2026. The an infection chain begins with a ClickFix social engineering assault, ensuing within the execution of a PowerShell command that results in the deployment of extra .NET downloaders and loaders.

This subsequently offers strategy to the principle elements, together with ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. That mentioned, it is value noting that the operation doesn’t all the time lead to ransomware deployment. Most often, the menace actors have been noticed covertly stealing lists of information after which particular information from the programs.

The operation is supported by a cluster of hacked WordPress websites that serve a number of capabilities –

  • Host malware levels
  • Run as command-and-control (C2) servers to ship directions
  • Retailer logs exfiltrated from victims

Test Level mentioned it was capable of glean extra insights into the marketing campaign because of the menace actor’s operational safety blunders that uncovered detailed an infection logs and screenshots from sufferer machines, in addition to the instruments used to mass-manage compromised web sites. As many as near 2,000 WordPress websites are estimated to have been hacked as a part of the marketing campaign.

A lot of the websites have been discovered to not solely run outdated variations of WordPress, but in addition put in plugins. One of many compromised web sites, as an illustration, runs a WordPress model from 2021, making it inclined to roughly 40 completely different vulnerabilities.

These websites are tampered with to serve pretend ClickFix-style CAPTCHA prompts to guests, successfully infecting themselves within the course of. The PowerShell command triggered utilizing this methodology acts as a conduit for a multi-step course of –

  • A stage 1 .NET downloader that stories statistics to the C2 server and masses the following stage
  • A stage 2 .NET downloader and loader that includes sandbox checks and extra logging mechanisms, and launches the principle elements
  • A stage 3 that features six elements:

    • SilentEncryptor, which encrypts both all at present contaminated computer systems or solely computer systems with given host names
    • NetworkShareScanner, which capabilities like an SMB/USB worm to unfold to different gadgets
    • VBS spreader, which propagates the malware to onerous disks and detachable media, scans the community, and laterally strikes through WMI
    • LockScreen, which blocks person enter and shows a ransom message with a fee QR code)
    • SimpleChatProxy, which is a customized chat software for speaking between the sufferer and operator
    • SilentDataCollector, which generates an inventory of all drives, encrypts it, and exfiltrates this record to the C2 server. The operator can add a command file to the server that the stealer reads to reap particular information.

Newer iterations of the stealer additionally implement additional options, together with a keylogger with legitimate e mail handle detection, exfiltration from WhatsApp, mapping and unmapping community shares, and capturing screenshots of person exercise each 30 seconds.

“An operator might challenge a WhatsApp search key phrase; each the online and desktop variations are supported,” Test Level mentioned. “The stealer waits till the sufferer turns into inactive after which makes use of WhatsApp automation to focus the search field, enter the required key phrase (contact identify), open the contact data, and seize a screenshot.”

Additional investigation has decided that the menace actors make use of a ZIP archive containing a PHP file (“uploader-installer.php”) to put in a customized WordPress plugin, which is used to create a must-use (MU) plugin file that is accountable for making a must-use (MU) plugin file within the “wp-content/mu-plugins” listing.

The plugin lets anybody in possession of legitimate credentials add arbitrary information, together with PHP information, to the WordPress web site to nearly any path underneath the WordPress root. The add of PHP information can pave the best way for distant code execution. As soon as the location has been interfered with, the plugin deactivates itself and self-deletes to sidestep detection.

The uploaded information embrace stolen knowledge from sufferer machines, with greater than 700 archives recognized from mid-Might to the tip of July 2026. Amongst these information are inner improvement information and instruments in what seems to be a case of the operator inadvertently infecting themselves. This features a customized automation utility named “fMain.frm” that is used to handle compromised WordPress websites.

“This automation instrument permits the botnet operator to mass-manage compromised WordPress pages,” Test Level mentioned. “It makes use of safe add and delete PHP scripts on compromised web sites to add or delete extra information, activate or deactivate fake-captcha ClickFix, activate or deactivate caching, and so forth.”

The compromised websites include a malicious “confirm” plugin that overlays the unique content material with a pretend CAPTCHA for non-Home windows guests. The plugin is activated after the menace actor uploads a file known as “activator.php,” after which it deletes itself.

As of July 24, 2026, the marketing campaign has compromised greater than 6,000 distinctive IP addresses. Most of them are situated within the U.S. (1,852), Russia (630), and India (630).

“StopAndProtect reveals how attackers can flip hundreds of poorly maintained WordPress websites right into a distributed felony infrastructure for malware supply, surveillance, knowledge theft, and ransomware,” Test Level’s Eli Smadja mentioned. 

“We urge organizations to be cautious of sudden CAPTCHA prompts that instruct them to repeat, paste, or run instructions, maintain their gadgets and safety software program up to date, and instantly go away any web site that asks them to carry out uncommon steps exterior the browser.”

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *