StopAndProtect Operation Abuses Thousands of Hacked WordPress Sites for Malware Distribution and Data Theft
A new cybercriminal operation dubbed StopAndProtect is leveraging thousands of compromised WordPress websites as infrastructure to distribute malware, control infected machines, and store exfiltrated data, including ransomware, worms, and credential stealers.

A newly identified cybercriminal operation, named StopAndProtect, has been discovered weaponizing thousands of compromised WordPress websites to serve as its core infrastructure. This operation uniquely combines file encryption with sophisticated data theft techniques, utilizing the compromised sites for malware distribution, command and control (C2), and the storage of sensitive exfiltrated information.
The threat actors behind StopAndProtect employ a comprehensive toolkit that includes ransomware, a worm capable of spreading across SMB and USB devices, a screen locker, and a credential stealer. The infection chain typically begins with a social-engineering tactic known as ClickFix, which tricks victims into executing a PowerShell command. This initial compromise leads to a multi-stage download and execution process involving .NET-based loaders, ultimately deploying the various functional components of the StopAndProtect toolkit.
Compromised WordPress sites are central to the operation's success. They are used to host malware stages, act as C2 servers for issuing commands to infected machines, and serve as repositories for logs and data stolen from victims. This reliance on a vast network of compromised websites allows the attackers to maintain a degree of anonymity and resilience, making attribution and takedown efforts more challenging.
Compounding the threat, significant operational security (OPSEC) failures by the malware's developer have inadvertently exposed a wealth of information. Researchers uncovered detailed infection logs from victims' machines, screenshots from compromised computers, and even the source code for tools used to manage the compromised WordPress sites at scale. This exposed data provides a rare glimpse into the operation's scope and methods.
Analysis of the exposed logs and management tools suggests that thousands of IP addresses have been affected, indicating a large-scale campaign targeting victims across numerous regions, with a notable concentration in the US, Russia, and India. The operation's modular design, employing a suite of malware components rather than a single piece, allows for diverse malicious activities, from encrypting files to silently exfiltrating documents and maintaining a live chat channel with victims.
The attackers exploit the widespread vulnerability of outdated WordPress installations and plugins. Many websites remain unpatched, harboring numerous security flaws, including SQL injection, authentication bypasses, and arbitrary file uploads. The StopAndProtect operation capitalizes on these weaknesses, initiating its infection chain through a deceptive ClickFix prompt presented on compromised sites.
The infection process involves several stages, starting with PowerShell scripts that communicate with C2 servers and download subsequent .NET-based loaders. These loaders perform sandbox checks, collect extensive telemetry, and then deploy the final payload, which can include ransomware, the worm, lockscreen, credential stealer, VBS spreader, or chat utility, depending on the attacker's objective for that specific victim.
This operation highlights the persistent threat posed by unpatched web infrastructure and the sophisticated ways in which attackers are leveraging compromised resources. The combination of ransomware, data theft, and the use of a vast, compromised network infrastructure makes StopAndProtect a significant and evolving threat to WordPress users and their visitors.