A large malware operation used close to 2,000 compromised WordPress websites as delivery and control points for attacks on Windows users, according to a new report from Check Point Research. The researchers said the activity is tied to the StopAndProtect ransomware family, which they first identified in mid-May before connecting it to a wider criminal system.

Check Point said the hijacked sites were not only used to distribute malicious code, but also to issue commands to infected machines and store data stolen from victims. The report describes an operation built from several tools working together, rather than a single malware strain.

Fake CAPTCHA led victims to infect their own systems

According to Check Point, the attack chain started with a fake CAPTCHA shown on an already-compromised website. The prompt, described as a ClickFix lure, instructed visitors to run a PowerShell command on their own computers.

That command allegedly installed malware designed to steal credentials and cryptocurrency wallet seed phrases. The same toolset could also spread across networks and USB drives, lock a victim’s screen, and in some cases deploy ransomware.

A broader toolkit behind StopAndProtect

Researchers said the campaign relied on a collection of criminal components with different roles. Some were used to encrypt files, others to quietly gather documents, while another functioned as a live chat channel between the attackers and infected users.

The report said the compromised WordPress sites became part of the attackers’ infrastructure. They hosted malware payloads, relayed commands, and kept stolen documents, screenshots, and activity logs from infected systems.

Operational mistakes exposed the scale of the campaign

Check Point said errors by the threat actor opened a rare window into the operation. Those mistakes exposed directories containing infection logs, screenshots from victims’ computers, and source code for tools used to manage hacked websites at scale.

The exposed data allowed researchers to quantify part of the campaign. Between mid-May and the end of July, they collected more than 31,000 screenshots and found over 700 archives containing stolen material, including documents, passwords, and cryptocurrency wallet files. Check Point also said it believes the attackers may have accidentally infected themselves.

More than 6,000 IPs were linked to infections

By July 24, Check Point had linked the operation to more than 6,000 unique IP addresses. The largest count identified in the report was in the United States with 1,852, followed by Russia and India with 630 each.

The researchers specifically said the malware targeted Windows users. The report did not state whether macOS or Linux systems were also affected, leaving that point unresolved.

What is confirmed so far

The confirmed picture from Check Point is that StopAndProtect was not operating as a simple ransomware dropper. Instead, it appears to have combined credential theft, surveillance, lateral spread, and file encryption while relying on a large network of hacked WordPress sites as criminal infrastructure.

For now, the clearest next step is further analysis of the exposed logs, screenshots, and source code uncovered by the researchers. Those materials may help map the full scope of the operation and clarify how the threat actor managed and expanded the campaign.

Source: decrypt.co