A newly uncovered malware operation dubbed StopAndProtect is remodeling hundreds of hacked WordPress web sites right into a sprawling felony command-and-control (C2) infrastructure.
The marketing campaign blends double-extortion ransomware with covert information theft, quietly harvesting delicate company paperwork, system screenshots, person credentials, and lively communication logs from compromised machines worldwide.
Inner logs uncovered by way of the menace actors’ operational safety failures reveal over 6,000 distinctive sufferer IP addresses throughout the globe, with the best an infection charges concentrated in the USA, Russia, and India.
The operators actively handle near 2,000 compromised WordPress domains, making a resilient, rotating pool of infrastructure to distribute payloads, preserve management channels, and retailer exfiltrated recordsdata.
Hackers Flip WordPress Websites Into C2 Servers
The preliminary compromise vector depends on misleading fake CAPTCHA lures injected straight into weak WordPress web sites.
When guests land on compromised pages, they’re introduced with a fraudulent human-verification immediate instructing them to repeat and paste a malicious PowerShell command into their terminal.

As soon as executed, the command initiates a multi-stage an infection sequence pushed by twin PowerShell scripts and modular .NET loaders, in the end deploying a flexible toolkit that features ransomware, credential stealers, display screen lockers, VBS spreaders, and USB community worms.
As detailed within the investigative report published by Check Point Research, the operation departs from standard smash-and-grab assaults by prioritizing intelligence gathering and selective monetization.
Menace actors conduct intensive doc enumeration, log keystrokes, map related community shares, seize periodic screenshots, and scrape native communication information earlier than deciding whether or not to deploy ransomware.

A number of compromised WordPress staging servers left uncovered PHP endpoints and open listing listings accessible to the general public, permitting safety researchers to examine inner exercise logs, sufferer telemetry, and uncooked supply code.
In a single notable occasion, the operator apparently contaminated their private machine and inadvertently uploaded inner improvement recordsdata, together with a customized Visible Fundamental 6 software used to mass-manage hijacked WordPress domains, toggle pretend CAPTCHA overlays, and deploy new payloads throughout the botnet.
The marketing campaign highlights the extreme dangers of unmaintained Content material Administration Methods. One analyzed web site had been working with out updates since 2021, exposing almost 40 unpatched vulnerabilities.
Unaddressed WordPress security flaws and outdated plugins present adversaries with persistent backdoors to transform respectable web sites into malicious relays.
Addressing these compromised endpoints is significant to disrupting trendy ransomware deployment tactics earlier than adversaries transfer laterally throughout inner networks.
Compromised web sites are not serving solely as easy phishing hosts or visitors redirectors; they’re now weaponized as absolutely purposeful C2 servers that mix malicious communications with respectable net visitors.
Web site directors should implement rigorous replace schedules throughout WordPress core recordsdata, lively themes, and third-party plugins whereas usually scanning for unauthorized PHP scripts, modified .htaccess recordsdata, and suspicious administrator accounts.
Finish customers ought to deal with any web site prompting terminal command execution as a direct compromise try, and safety groups should monitor endpoint telemetry for unauthorized PowerShell execution and anomalous outbound information transfers.
IOCs
| compromised web sites | maximumrock[.]ro platinumcar[.]ca norakremer.co[.]uk pharmart[.]ae ksr-racingparts[.]com |
| compromised base C&C web sites | v-k.com[.]ua www.lapellelaser[.]pl www.parsrulman[.]com mectcalcutta[.]com discherniation[.]com |
| PowerShell script stage 1 | cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0 |
| PowerShell script stage 2 | cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9 |
| stage 1 – downloader | 99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b 8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5 4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504 |
| stage 2 – downloader & loader | 9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527 7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c 976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153 |
| stage 3 – encryptor | b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489 65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143 0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40 |
| stage 3 – SMB/USB worm | 8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4 10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0 f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41 |
| stage 3 – lockscreen | 11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e 2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c 38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9 |
| stage 3 – credential stealer | 23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70 |
| stage 3 – VBS spreader | b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad |
| stage 3 – chat utility | 3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9 3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8 |
Strengthen Your SOC by Accelerating Menace Detection & Speedy Investigations. -> Integrate ANY.RUN With Your SOC Now.