StopAndProtect Operation Exploits Thousands of Compromised WordPress Sites for Data Theft and Ransomware Attacks
The StopAndProtect operation has surfaced as a formidable cybersecurity threat, targeting thousands of compromised WordPress sites to facilitate data theft and ransomware attacks. This operation employs a sophisticated infrastructure that integrates file encryption with data exfiltration, utilizing hacked websites as command and control (C&C) servers to manage infected machines and store stolen data. Research findings indicate a complex network of malware components that function in concert, underscoring the urgent need for enhanced vigilance in cybersecurity practices.
Operational Overview
First identified in May 2026, the StopAndProtect operation utilizes a ClickFix social-engineering technique to deceive victims into executing a PowerShell command. This triggers a multi-stage infection process that involves .NET-based downloaders and loaders, ultimately deploying various malicious components, including ransomware, a credential stealer, and a chat utility for communication between attackers and victims. While the operation is named after its ransomware component, it often prioritizes the silent exfiltration of files over encryption.
The operational security oversights of the attackers have inadvertently revealed a wealth of information, including detailed logs from infected machines and the source code of their management tools. This exposure has provided researchers with insights into the scale of the operation, which has impacted thousands of IP addresses across multiple countries, primarily in the United States, Russia, and India.
Infection Chain and Technical Details
The infection chain initiates when a victim visits a compromised WordPress site and encounters a deceptive CAPTCHA prompt. If the victim interacts with this prompt, they unknowingly execute a PowerShell script that leads to further stages of infection. The process unfolds as follows:
- ClickFix → PowerShell script 1 → PowerShell script 2 → Stage 1 (loader) → Stage 2 (downloader & loader) → Stage 3 (components: encryptor, SMB/USB worm, lockscreen, credential stealer, VBS spreader, chat utility).
The initial PowerShell script logs execution details and downloads subsequent stages, which include a downloader that reports statistics back to the C&C server. The final stage encompasses various malicious payloads, including a ransomware component capable of encrypting files based on specific criteria, and a stealer that gathers sensitive data from the victim’s machine.
Data Exfiltration and Victim Impact
The StopAndProtect operation has proven particularly adept at exfiltrating sensitive data from its victims. Researchers have identified over 700 encrypted ZIP archives containing stolen files, including documents, passwords, and screenshots. The naming conventions of these archives indicate a systematic approach to data collection, with files often labeled according to their content and the machine from which they were extracted.
During the monitoring period, approximately 31,000 screenshots were collected from victims’ machines, revealing personal information and activities, including ransom messages and interactions with antivirus software. This level of detail highlights the invasive nature of the StopAndProtect operation and the potential for significant personal and organizational harm.
Conclusion and Recommendations
The StopAndProtect operation exemplifies the evolving tactics of cybercriminals, who exploit compromised infrastructure to execute complex attacks. Organizations must prioritize the security of their web applications, especially those built on platforms like WordPress, by ensuring regular updates and patching of vulnerabilities. Implementing robust monitoring and incident response strategies can help mitigate the risks associated with such sophisticated threats.
For more detailed insights into the StopAndProtect operation, including technical analysis and statistics, refer to the full report by Check Point Research here.
Published on 2026-08-19 20:20:00 • By the Editorial Desk

