StopAndProtect Turns WordPress Sites into Distributed Malware Network
A sophisticated cybercrime operation called StopAndProtect has been discovered to have compromised nearly 2,000 legitimate WordPress websites, turning them into a distributed attack network that spreads malware, steals crypto wallet files, and deploys ransomware. The attackers used a clever tactic to infect victims' machines by weaponizing the exact security behavior users trust: CAPTCHA verification boxes.
The operation's infrastructure strategy is what makes it unusually effective. Instead of running dedicated command-and-control servers, the attackers repurposed compromised WordPress sites to host malware downloads, relay commands to infected machines, and store exfiltrated data. This blending into legitimate internet activity makes it harder for security teams to identify and take down the attackers' infrastructure.
The researchers found that the operation collected over 700 archives of stolen data from victim machines, including documents, saved passwords, and files associated with cryptocurrency wallets. The malware actively searches infected machines for wallet-related files, including seed phrases, keystore files, and wallet application data.
The campaign's success is attributed to its ability to target small business pages, personal blogs, and community sites that run outdated WordPress core versions and unpatched plugins. Check Point found one compromised site running a five-year-old installation with approximately 40 known vulnerabilities.