StopAndProtect Hijacks 2,000 WordPress Sites to Spread Malware and Ransomware

Last updated: August 19, 2026 Reading time: 4 minutes
Disclosure
Share
StopAndProtect Hijacks 2,000 WordPress Sites to Spread Malware and Ransomware
  • A new malware operation called StopAndProtect hijacks WordPress sites to build hidden command centers.
  • The group already controls close to 2,000 stolen WordPress domains around the world.
  • Fake CAPTCHA pop-ups trick visitors into typing a dangerous command into their own computer.

Hackers have found a clever new way to hide their attacks. They break into weak WordPress sites first. Then they turn those sites into secret control hubs. Researchers named this operation StopAndProtect. It steals data first, then locks victims’ files for ransom later. Attackers already run close to 2,000 hijacked WordPress sites.

These sites host stolen files, spread malware, and pass secret commands. Leaked logs show more than 6,000 victims so far. Most victims live in the United States, Russia, and India, according to Check Point Research. Compromised sites act as more than simple traffic redirectors now. They work as full command posts that blend in with normal web traffic.

How the Attack Starts and Spreads

The attack begins with a trick, not a break-in. Hackers plant a fake CAPTCHA box on weak WordPress sites. This box looks like a normal human-check test. But it asks visitors to copy a command and paste it into their computer.

Once someone runs that command, the real trouble begins. The command launches a chain of hidden scripts. Two PowerShell scripts run first, one after the other. Then small loader programs pull in more harmful tools. This chain builds slowly and quietly, step by step. That slow pace makes the attack harder to spot.

The final toolkit does many jobs at once. It can lock a victim’s screen, steal passwords, and spread through USB drives. It can also search shared folders and copy chat messages. Researchers say this approach differs from typical smash-and-grab hacks.

Attackers study each victim carefully before making their next move, according to a report by Check Point Research. Some hijacked sites even carry names like ordinary small business pages, which helps them blend in.

What the Hackers Steal Before They Strike

StopAndProtect blends two crimes into one operation. It steals data quietly, then threatens to leak it for payment. Before locking any files, the malware looks around first. It counts documents, checks connected drives, and takes screenshots.

It even copies saved chat logs, including WhatsApp contact details. Only after gathering enough data does it decide whether to strike. This method lets attackers pick their richest targets first. That is what makes this campaign feel less like a smash-and-grab job and more like patient spying.

Mistakes by the hackers themselves exposed parts of this operation. Some servers left open folders that anyone could browse freely. Researchers found internal logs, victim details, and raw code inside them.

One operator seemingly infected their own computer by accident. That slip revealed a custom tool built to manage the whole network. The tool can turn fake CAPTCHA pop-ups on and off. It also pushes out new malware to infected sites at will.

Old and neglected websites made this whole campaign possible. One infected site had not been updated since 2021. That single site carried nearly 40 unfixed security flaws, per the report. Weak plugins and outdated WordPress files leave doors wide open. Hackers walk right through those doors and weaponize honest websites. Small business owners often run these sites and rarely check for updates.

How Website Owners and Users Can Stay Safe

Website owners carry the biggest share of responsibility here. They must update WordPress, its themes, and every plugin often. Regular scans for unknown PHP files matter just as much.

A recent example of why patching matters: the Renown Gallery plugin, installed on over one million sites, was found to have a critical remote code execution vulnerability due to unfiltered user input, which allowed attackers to exploit URLs and shortcodes to compromise sites.

Admins should also watch for strange new administrator accounts appearing. A single missed update can hand a whole site to strangers. Website owners should also remove any plugin they no longer use.

Regular internet users need to stay alert as well. No real website ever asks you to paste a command into your computer. If a site tries this, treat it as a serious warning sign. Close the page right away and avoid typing anything at all. Security teams should also watch for unusual PowerShell activity on company devices. Sudden data transfers to unknown servers deserve quick attention too.

This campaign shows how ordinary websites can turn dangerous overnight. A single unpatched plugin can quietly become part of a criminal network. Staying updated is no longer optional for site owners. It remains the simplest defense against attacks like StopAndProtect. Quick checks and fast action can stop this threat before it spreads, according to Check Point Research.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts