Cybersecurity researchers have identified a large scale cybercrime operation called StopAndProtect that is abusing nearly 2,000 compromised WordPress websites to distribute malware, control infected systems, and collect sensitive information from victims. According to Check Point Research, the operation uses a combination of malicious tools instead of a single malware family, allowing attackers to perform different activities including file encryption, data theft, system monitoring, and communication with affected users. The researchers began tracking the campaign after discovering a ransomware family named StopAndProtect in mid May 2026. The attack process starts with a ClickFix based social engineering technique, where compromised websites display fake CAPTCHA prompts designed to trick visitors into executing PowerShell commands. These commands initiate a multi stage infection process that downloads additional .NET based loaders and malware components onto targeted systems.
The StopAndProtect operation relies heavily on compromised WordPress websites that serve multiple purposes throughout the attack lifecycle. Researchers found that these hacked websites are used to host malware stages, operate command and control servers, and store information stolen from infected devices, including documents, screenshots, and activity logs. Check Point estimated that close to 2,000 WordPress websites have been compromised as part of the campaign, with many affected sites running outdated WordPress versions and vulnerable plugins. One compromised website examined by researchers was running a WordPress version from 2021, making it vulnerable to around 40 known security flaws. Attackers modify these websites to display fake ClickFix style CAPTCHA pages to visitors, creating an infection pathway that encourages users to perform actions that lead to malware execution.
Researchers explained that the malware deployment process involves multiple stages. The first stage includes a .NET downloader that communicates with attacker controlled infrastructure, reports statistics, and loads additional components. The second stage contains another .NET downloader and loader equipped with sandbox detection and logging capabilities before launching the main tools. The final stage includes several malware components such as SilentEncryptor, which encrypts files on infected computers based on attacker instructions, NetworkShareScanner, which spreads through SMB and USB connections, and a VBS spreader that helps distribute malware through storage devices and networks using WMI. The toolkit also includes LockScreen, which blocks user access and displays ransom messages with payment QR codes, SimpleChatProxy, which provides a communication channel between attackers and victims, and SilentDataCollector, which gathers file information and sends selected data to command and control servers. Newer versions of the information stealing component have added features including keylogging, valid email address detection, WhatsApp searches, network share management, and screenshots captured every 30 seconds.
Further analysis revealed that attackers used a ZIP archive containing a PHP file named uploader-installer.php to install a malicious WordPress plugin. The plugin created a must use plugin file inside the wp content/mu plugins directory, allowing attackers with valid credentials to upload arbitrary files, including PHP files, across the WordPress installation. This capability could enable remote code execution on compromised websites. After completing its activity, the plugin disables itself and removes related files to reduce the possibility of detection. Check Point researchers discovered more than 700 stolen data archives uploaded between mid May and the end of July 2026, including internal development files and tools. Among the discovered files was a custom automation utility named fMain.frm, which appeared to be used by attackers to manage compromised WordPress websites at scale by uploading and deleting files, activating or disabling fake CAPTCHA campaigns, and controlling infected pages.
As of July 24, 2026, the campaign had compromised more than 6,000 unique IP addresses, with the highest number of affected systems reported in the United States, Russia, and India. Check Point researchers said the StopAndProtect operation demonstrates how poorly maintained WordPress websites can be transformed into distributed criminal infrastructure for malware delivery, surveillance, ransomware deployment, and information theft. Security experts have advised organizations to keep website platforms, plugins, devices, and security software updated to reduce exposure to such attacks. Users have also been warned to remain cautious of unexpected CAPTCHA prompts that ask them to copy, paste, or execute commands, as these techniques are increasingly being used to deliver malware outside normal browser activity.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





