2,000 WordPress Sites Compromised for Ransomware Operation
Nearly 2,000 WordPress sites have been compromised and turned into criminal infrastructure by a threat actor known as StopAndProtect. The malware operation was first discovered in mid-May and has since grown to compromise over 6,000 unique IP addresses, with 1,852 of those being in the United States.
The attack begins with a fake CAPTCHA on a compromised website, instructing victims to run a PowerShell command that installs malware. This malware can steal credentials, cryptocurrency wallet seed phrases, spread through networks and USB drives, lock screens, and deploy ransomware.
Check Point researchers believe the attackers accidentally infected themselves, exposing internal files and tools used to manage compromised sites. The operation is described as a 'whole toolkit of criminal software working together,' with different components performing tasks such as encrypting files, stealing documents, and locking screens.