mimile
Back to feed

Check Point uncovers StopAndProtect cybercrime ring using 2,000 WordPress sites

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Check Point uncovers StopAndProtect cybercrime ring using 2,000 WordPress sites

Check Point Research uncovered a global cybercrime ring dubbed StopAndProtect that hijacked around 2,000 WordPress sites and infected 5,000 computers. The operation used compromised WordPress installations to deliver malware, conduct surveillance, steal data, and distribute ransomware. The discovery raises concerns about the security of outdated WordPress versions and third-party plugins.

Key Facts

  • Check Point Research identified a cybercrime ring named StopAndProtect that compromised approximately 2,000 WordPress sites and 5,000 computers worldwide.
  • The operation used hijacked WordPress domains to distribute ransomware, steal data, conduct surveillance, and deliver malware.
  • One compromised WordPress site was running a five-year-old version of the CMS with around 40 known vulnerabilities.
  • WordPress powers about 43% of all websites globally, making it the most widely used content management system.
  • Check Point researcher Eli Smadja urged organizations to be cautious of unexpected CAPTCHA prompts and to keep software updated.

The StopAndProtect Operation

Check Point Research uncovered the StopAndProtect cybercrime ring after noticing operational mistakes such as screenshots, victim logs, internal tools, and files referencing hijacked domains. The operation compromised both the WordPress core software and third-party plugins, turning legitimate websites into criminal infrastructure. Eli Smadja of Check Point Research stated that StopAndProtect demonstrates how attackers can convert thousands of poorly maintained WordPress sites into a distributed network for malware delivery, surveillance, data theft, and ransomware. The name StopAndProtect was initially applied to ransomware discovered earlier in 2026, but researchers extended it to the entire operation after finding it distributed more than just ransomware.

WordPress Security Risks

WordPress has long been a target for hackers seeking to host malware and operate botnets, with several significant incidents over its history. The platform remains free and open source, and its ease of setup through installation scripts and web builder plugins contributes to widespread use but also to inconsistent security maintenance. One WordPress site involved in the StopAndProtect operation was running a five-year-old version of the CMS compromised by approximately 40 vulnerabilities. Smadja advised organizations to be cautious of unexpected CAPTCHA prompts that instruct users to copy, paste, or run commands, and to immediately leave any website that requests unusual steps outside the browser.

1 source

Check Point uncovers StopAndProtect cybercrime ring using 2,000 WordPress sites