As cited
Copy frozen at (site build).
threat intel
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Researchers identified StopAndProtect, a large-scale operation abusing thousands of hacked WordPress sites as infrastructure to deliver ransomware, data-stealing malware, and other tools via ClickFix social engineering attacks. The campaign exploits outdated WordPress installations and plugins, using compromised sites to host malware stages, command-and-control servers, and stolen victim data including documents, passwords, wallets, and screenshots. Operational security failures exposed detailed logs showing over 6,000 unique infected IP addresses, mostly in the United States, Russia, and India, along with the attackers' own project files and automation tools written in Visual Basic 6.
Why it matters: Organizations running WordPress sites must audit and patch all WordPress core and plugin versions immediately, as unpatched installations from 2021 and earlier are primary targets. Security teams should monitor for ClickFix prompts, PowerShell execution from unknown sources, and indicators of compromise including the listed IOCs, malicious PHP files, and must-use plugins in wp-content/mu-plugins directories.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Researchers identified StopAndProtect, a large-scale operation abusing thousands of hacked WordPress sites as infrastructure to deliver ransomware, data-stealing malware, and other tools via ClickFix social engineering attacks. The campaign exploits outdated WordPress installations and plugins, using compromised sites to host malware stages, command-and-control servers, and stolen victim data including documents, passwords, wallets, and screenshots. Operational security failures exposed detailed logs showing over 6,000 unique infected IP addresses, mostly in the United States, Russia, and India, along with the attackers' own project files and automation tools written in Visual Basic 6.
Why it matters: Organizations running WordPress sites must audit and patch all WordPress core and plugin versions immediately, as unpatched installations from 2021 and earlier are primary targets. Security teams should monitor for ClickFix prompts, PowerShell execution from unknown sources, and indicators of compromise including the listed IOCs, malicious PHP files, and must-use plugins in wp-content/mu-plugins directories.
- Source published
- First seen by Cybersecurity Tracker