StopAndProtect Campaign Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
This digest was compiled by AI from multiple sources — links to the originals are below.

Check Point researchers identify a global cybercrime operation dubbed StopAndProtect that uses nearly 2,000 hacked WordPress sites to distribute malware and steal victim data. The campaign, discovered in mid-May 2026, deploys a toolkit of ransomware, credential stealers, and a lock-screen component while its operators exfiltrate files, screenshots, and activity logs.
Key Facts
- Check Point Research identified the StopAndProtect campaign in mid-May 2026 after discovering a ransomware family of the same name.
- The campaign uses an estimated 2,000 hacked WordPress sites to host malware, run command-and-control servers, and store logs exfiltrated from victims.
- The infection chain starts with a ClickFix social engineering attack that executes a PowerShell command and deploys .NET downloaders and loaders.
- The toolkit includes ransomware, an SMB/USB worm, LockScreen, a VBS spreader, a chat utility, and a credential stealer.
- Most compromised sites run outdated WordPress versions and plugins; one site runs a WordPress version from 2021 vulnerable to roughly 40 flaws.
Compromised WordPress Infrastructure
Check Point researchers estimate that close to 2,000 WordPress sites have been hacked to support the StopAndProtect campaign. These sites host malware stages, run as command-and-control servers to send instructions, and store logs exfiltrated from victims. Most of the compromised sites run outdated versions of WordPress and installed plugins. One compromised website runs a WordPress version from 2021, leaving it susceptible to roughly 40 different vulnerabilities. Check Point gained access to detailed infection logs and screenshots from victim machines because of operational security blunders by the threat actor.
Attack Chain and Payloads
The infection chain begins with a ClickFix social engineering attack that executes a PowerShell command. The PowerShell command acts as a conduit for a stage 1 .NET downloader that reports statistics to the C2 server and loads the next stage. A stage 2 .NET component then loads the main malware modules, including ransomware, an SMB/USB worm, LockScreen, a VBS spreader, a chat utility, and a credential stealer. The operation does not always result in ransomware deployment; in most cases, the threat actors covertly steal lists of files and then specific files from the systems. The operation relies on a toolkit of criminal software that includes components to encrypt files, silently steal documents, lock the screen, and provide a live chat between the attackers and their victims.
1 source
StopAndProtect Campaign Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data



