StopAndProtect Ransomware Campaign Compromises Nearly 2,000 WordPress Sites
A cybercrime operation called StopAndProtect has compromised nearly 2,000 WordPress sites to steal cryptocurrency wallet files and deploy ransomware. The campaign, which started in mid-May 2026, has infected over 6,000 unique IP addresses across the US, Russia, and India.
The attackers use a social-engineering technique called ClickFix, where victims are prompted to run malicious PowerShell commands on their own machines. This downloads a .NET loader that pulls in malware components, including credential stealers and modules to locate and exfiltrate crypto wallet files.
Many of the compromised sites were running outdated WordPress versions from as far back as 2021. The attackers' hybrid approach combines selective file encryption with data theft and ongoing user surveillance, making it a direct threat against digital asset holders.