Check Point Research says a criminal group it tracks as StopAndProtect has turned nearly 2,000 compromised WordPress sites into a malware distribution network aimed at Windows users, including people with cryptocurrency wallets. According to the researchers, the operation used legitimate but poorly maintained blogs and business websites to host fake verification pages and malware components.
The campaign was designed to steal cryptocurrency wallet seed phrases, saved passwords and files from infected computers. Check Point said evidence found on the attackers’ own exposed servers points to a wide operation, with more than 6,000 unique IP addresses infected by July 24 and thousands of screenshots and stolen file archives stored by the group.
Fake CAPTCHA pages were the entry point
The infection chain described by Check Point starts with a phishing page disguised as a CAPTCHA check. Windows users are prompted to copy and paste a PowerShell command, which then downloads .NET-based malware onto the machine.
Researchers said the payload can extract saved passwords, crypto wallet seeds and other information. It can also copy files from USB drives and shared folders, log keystrokes, take screenshots every 30 seconds and access WhatsApp in order to capture a victim’s contact list.
Check Point added that the same malware set could also encrypt the victim’s machine for ransomware, making the campaign broader than a simple credential-theft operation.
Compromised WordPress sites served several roles
Rather than relying on a small number of attacker-controlled domains, the group allegedly spread its infrastructure across almost 2,000 hacked WordPress sites. Those sites appeared to visitors as normal blogs or business pages, which helped mask the malicious activity.
According to the report, the attackers used WordPress domains to host ransomware payloads, command-and-control infrastructure and storage for stolen data. Check Point said this setup let the criminals avoid paying for dedicated infrastructure while allowing a single server to manage malware delivery, redirects and exfiltrated files.
The researchers said they identified nearly 40 WordPress vulnerabilities dating back to 2021 that were present in the compromised environment.
Exposed attacker servers showed the scale
Check Point said open directories and log files on the attackers’ own servers exposed how the campaign was run. Among the files was a Visual Basic 6 automation tool that could remotely switch phishing pages on or off, change redirects and push malware updates.
Files linked to that tool reportedly included a list of nearly 2,000 hacked domains. The logs also showed that the campaign had infected more than 6,000 unique IP addresses by July 24.
The United States accounted for 1,852 of those IPs, while Russia and India each accounted for 630, according to the researchers. Between mid-May and the end of July, Check Point found more than 700 archives of stolen files, and one server directory contained more than 20,000 screenshots taken from victims’ computers.
What is confirmed so far
The findings tie the StopAndProtect activity to a large pool of compromised WordPress websites and a malware chain that specifically targets data valuable to crypto users, including wallet seed phrases. The report also indicates the campaign relied on exposed infrastructure and basic automation to operate at scale.
Based on the published findings, the confirmed next step is further tracking of the infrastructure and compromised sites tied to the operation. The report does not say whether the affected WordPress sites have all been cleaned up or whether the campaign has been disrupted.
Source: Cryptopolitan