CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4608

As cited

Copy frozen at (site build).

threat intel

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Researchers identified StopAndProtect, a large-scale operation abusing thousands of hacked WordPress sites as infrastructure to deliver ransomware, data-stealing malware, and other tools via ClickFix social engineering attacks. The campaign exploits outdated WordPress installations and plugins, using compromised sites to host malware stages, command-and-control servers, and stolen victim data including documents, passwords, wallets, and screenshots. Operational security failures exposed detailed logs showing over 6,000 unique infected IP addresses, mostly in the United States, Russia, and India, along with the attackers' own project files and automation tools written in Visual Basic 6.

Why it matters: Organizations running WordPress sites must audit and patch all WordPress core and plugin versions immediately, as unpatched installations from 2021 and earlier are primary targets. Security teams should monitor for ClickFix prompts, PowerShell execution from unknown sources, and indicators of compromise including the listed IOCs, malicious PHP files, and must-use plugins in wp-content/mu-plugins directories.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Researchers identified StopAndProtect, a large-scale operation abusing thousands of hacked WordPress sites as infrastructure to deliver ransomware, data-stealing malware, and other tools via ClickFix social engineering attacks. The campaign exploits outdated WordPress installations and plugins, using compromised sites to host malware stages, command-and-control servers, and stolen victim data including documents, passwords, wallets, and screenshots. Operational security failures exposed detailed logs showing over 6,000 unique infected IP addresses, mostly in the United States, Russia, and India, along with the attackers' own project files and automation tools written in Visual Basic 6.

Why it matters: Organizations running WordPress sites must audit and patch all WordPress core and plugin versions immediately, as unpatched installations from 2021 and earlier are primary targets. Security teams should monitor for ClickFix prompts, PowerShell execution from unknown sources, and indicators of compromise including the listed IOCs, malicious PHP files, and must-use plugins in wp-content/mu-plugins directories.

VendorsMicrosoftCheck PointWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary