2,000 WordPress Sites Turned into Crypto-Stealing Traps
Crypto users are being targeted by a group known as StopAndProtect, who have hacked nearly 2,000 poorly maintained WordPress sites to host malware that steals cryptocurrency wallet seeds, passwords, and files from infected Windows computers. The group's campaign has been ongoing since mid-May, with the first ransomware sample spotted in May.
The most alarming part for crypto holders is that these takeovers are distributed across legitimate sites that appear to be standard business blogs or websites. According to Check Point Research, the attackers have taken a different route by hosting their malware on WordPress domains that they did not have to pay for or compromise.
The phishing campaign tricks Windows users into believing that they need to complete a CAPTCHA test to gain access to a website. However, the CAPTCHA is actually a scam, and users who try to complete it will be instructed to copy and paste a PowerShell command into their command prompt. This command then begins downloading .NET payloads that allow the attacker to extract saved passwords, crypto wallet seeds, and other data from the compromised computer.